📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global supply_chain Software Development and Technology HIGH 5h Global apt Government/Critical Infrastructure CRITICAL 7h Global vulnerability Enterprise Software / Data Analytics CRITICAL 7h Global vulnerability Artificial Intelligence and Technology HIGH 11h Global general Technology and Artificial Intelligence MEDIUM 14h Global general Technology and Artificial Intelligence HIGH 15h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global malware Software Development CRITICAL 1d Global supply_chain Software Development and Technology HIGH 5h Global apt Government/Critical Infrastructure CRITICAL 7h Global vulnerability Enterprise Software / Data Analytics CRITICAL 7h Global vulnerability Artificial Intelligence and Technology HIGH 11h Global general Technology and Artificial Intelligence MEDIUM 14h Global general Technology and Artificial Intelligence HIGH 15h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global malware Software Development CRITICAL 1d Global supply_chain Software Development and Technology HIGH 5h Global apt Government/Critical Infrastructure CRITICAL 7h Global vulnerability Enterprise Software / Data Analytics CRITICAL 7h Global vulnerability Artificial Intelligence and Technology HIGH 11h Global general Technology and Artificial Intelligence MEDIUM 14h Global general Technology and Artificial Intelligence HIGH 15h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global malware Software Development CRITICAL 1d
Vulnerabilities

CVE-2026-1610

High
A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded cre
CWE-259 — Weakness Type
Published: Jan 29, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
8.1
🔗 NVD Official
📄 Description (English)

A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been made public and could be used.

🤖 AI Executive Summary

Tenda AX12 Pro V2 firmware contains hard-coded credentials in the Telnet service, allowing remote attackers to gain unauthorized access with high complexity exploitation. This vulnerability affects widely deployed networking equipment in Saudi organizations, particularly in government and enterprise environments. While a patch is available, the public disclosure and remote exploitability pose significant risk to unpatched systems.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 26, 2026 04:49
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi government agencies, military installations, and large enterprises using Tenda networking equipment for network infrastructure. Banking sector organizations (SAMA-regulated) using these devices for branch connectivity face authentication bypass risks. Telecommunications providers (STC, Mobily) and energy sector organizations may have these devices in network perimeters. Healthcare facilities and educational institutions with Tenda equipment are also at risk. The hard-coded credentials could enable lateral movement within critical infrastructure networks.
🏢 Affected Saudi Sectors
Government and Public Administration Banking and Financial Services Telecommunications Energy and Utilities Healthcare Education Defense and Military Critical Infrastructure
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Tenda AX12 Pro V2 devices running firmware version 16.03.49.24_cn or earlier using network scanning tools
2. Isolate affected devices from critical network segments if patching cannot be completed immediately
3. Disable Telnet service on all Tenda devices and use SSH exclusively for management
4. Change all default credentials and implement strong access controls

PATCHING GUIDANCE:
1. Download latest firmware from Tenda official website (verify authenticity)
2. Apply firmware updates during maintenance windows with change management approval
3. Test updates in non-production environment first
4. Document all patched devices and maintain inventory

COMPENSATING CONTROLS:
1. Implement network segmentation - restrict Telnet access to management VLANs only
2. Deploy firewall rules blocking port 23 (Telnet) from untrusted networks
3. Enable logging and monitoring of all Telnet connection attempts
4. Implement intrusion detection signatures for Telnet exploitation attempts
5. Deploy network access control (NAC) to prevent unauthorized device connections

DETECTION RULES:
1. Monitor for Telnet connections to Tenda devices from unexpected sources
2. Alert on multiple failed authentication attempts followed by successful Telnet sessions
3. Track firmware version changes on Tenda devices
4. Monitor for suspicious command execution via Telnet service
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة Tenda AX12 Pro V2 التي تعمل بإصدار البرنامج الثابت 16.03.49.24_cn أو أقدم باستخدام أدوات فحص الشبكة
2. عزل الأجهزة المتأثرة عن قطاعات الشبكة الحرجة إذا لم يكن التصحيح ممكناً فوراً
3. تعطيل خدمة Telnet على جميع أجهزة Tenda واستخدام SSH حصرياً للإدارة
4. تغيير جميع بيانات الاعتماد الافتراضية وتنفيذ ضوابط وصول قوية

إرشادات التصحيح:
1. تحميل أحدث إصدار من البرنامج الثابت من موقع Tenda الرسمي (التحقق من الأصالة)
2. تطبيق تحديثات البرنامج الثابت خلال نوافذ الصيانة مع موافقة إدارة التغيير
3. اختبار التحديثات في بيئة غير الإنتاج أولاً
4. توثيق جميع الأجهزة المصححة والحفاظ على المخزون

الضوابط البديلة:
1. تنفيذ تقسيم الشبكة - تقييد وصول Telnet إلى شبكات إدارة فقط
2. نشر قواعد جدار الحماية لحظر المنفذ 23 من الشبكات غير الموثوقة
3. تفعيل تسجيل ومراقبة جميع محاولات اتصال Telnet
4. تنفيذ توقيعات كشف التطفل لمحاولات استغلال Telnet
5. نشر التحكم في الوصول إلى الشبكة لمنع اتصالات الأجهزة غير المصرح بها

قواعد الكشف:
1. مراقبة اتصالات Telnet بأجهزة Tenda من مصادر غير متوقعة
2. تنبيهات محاولات المصادقة الفاشلة المتعددة متبوعة بجلسات Telnet الناجحة
3. تتبع تغييرات إصدار البرنامج الثابت على أجهزة Tenda
4. مراقبة تنفيذ الأوامر المريبة عبر خدمة Telnet
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information security policies and procedures A.6.1.2 - Access control and authentication mechanisms A.8.2.1 - User access management A.8.2.3 - Management of privileged access rights A.8.3.1 - Password management A.9.2.1 - User endpoint devices A.9.4.1 - Event logging A.9.4.2 - Protection of log information
🔵 SAMA CSF
ID.AM-2 - Software platforms and applications are inventoried PR.AC-1 - Identities and credentials are issued and managed PR.AC-2 - Physical access is managed PR.AC-3 - Remote access is managed PR.AC-4 - Access rights and privileges are managed DE.AE-1 - A baseline of network operations is established DE.CM-1 - The network is monitored to detect potential cybersecurity events
🟡 ISO 27001:2022
5.3 - Segregation of duties 6.2 - People screening 8.1 - Operational planning and control 8.2 - Supply chain relationships 8.3 - Information and communication A.5.1.1 - Policies for information security A.6.1.2 - Access to information and other associated assets A.8.2 - User access management A.8.3 - User responsibilities A.9.2 - User endpoint devices A.9.4 - Logging
🟣 PCI DSS v4.0.1
Requirement 1 - Install and maintain a firewall configuration Requirement 2 - Do not use vendor-supplied defaults Requirement 7 - Restrict access to data by business need-to-know Requirement 8 - Identify and authenticate access to system components Requirement 10 - Track and monitor all access to network resources
📦 Affected Products / CPE 1 entries
tenda:ax12_pro_firmware:16.03.49.24_cn
📊 CVSS Score
8.1
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityH — High
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.1
CWECWE-259
EPSS0.02%
Exploit No
Patch ✓ Yes
Published 2026-01-29
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-259
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.