CVE-2026-11493: Weak Password Requirements in Tenda AC15
A weakness in the Tenda AC15 router version 15.03.05.19 involves weak password requirements related to an unknown function in the Samba configuration file /etc_ro/smb.conf. This vulnerability can only be exploited from within the local network and requires a high level of attack complexity. The exploit is publicly available but is considered difficult to execute. The CVSS score is low, reflecting limited impact and exploitability.
AI Analysis
Technical Summary
CVE-2026-11493 identifies a vulnerability in Tenda AC15 version 15.03.05.19 where weak password requirements exist due to an issue in an unspecified function of the Samba component's configuration file (/etc_ro/smb.conf). The vulnerability is exploitable only by attackers with local network access and requires high attack complexity. No privilege or user interaction is needed, but the overall impact and exploitability are low. The exploit code is publicly available, but no known exploits in the wild have been reported. No official patch or remediation guidance has been provided by the vendor.
Potential Impact
The vulnerability could allow an attacker on the local network to exploit weak password requirements in the Samba service configuration, potentially leading to unauthorized access or other security issues related to authentication. However, the low CVSS score (2.3) and high attack complexity indicate limited practical impact and difficulty in exploitation. There are no reports of active exploitation in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or workaround is currently documented, users should restrict local network access to trusted devices and monitor for unusual activity related to Samba services. Follow up with Tenda for any forthcoming security updates addressing this issue.
CVE-2026-11493: Weak Password Requirements in Tenda AC15
Description
A weakness in the Tenda AC15 router version 15.03.05.19 involves weak password requirements related to an unknown function in the Samba configuration file /etc_ro/smb.conf. This vulnerability can only be exploited from within the local network and requires a high level of attack complexity. The exploit is publicly available but is considered difficult to execute. The CVSS score is low, reflecting limited impact and exploitability.
CVSS v4.0
Score 2.3low
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-11493 identifies a vulnerability in Tenda AC15 version 15.03.05.19 where weak password requirements exist due to an issue in an unspecified function of the Samba component's configuration file (/etc_ro/smb.conf). The vulnerability is exploitable only by attackers with local network access and requires high attack complexity. No privilege or user interaction is needed, but the overall impact and exploitability are low. The exploit code is publicly available, but no known exploits in the wild have been reported. No official patch or remediation guidance has been provided by the vendor.
Potential Impact
The vulnerability could allow an attacker on the local network to exploit weak password requirements in the Samba service configuration, potentially leading to unauthorized access or other security issues related to authentication. However, the low CVSS score (2.3) and high attack complexity indicate limited practical impact and difficulty in exploitation. There are no reports of active exploitation in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or workaround is currently documented, users should restrict local network access to trusted devices and monitor for unusual activity related to Samba services. Follow up with Tenda for any forthcoming security updates addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-07T10:18:43.938Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a26623fe29bf47b50ad3356
Added to database: 06/08/2026, 06:33:35 UTC
Last enriched: 06/15/2026, 08:41:06 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.