B
今週中
Tenda製のルーター AC1206 および AC18 において、認証回避が可能な3つの深刻な脆弱性
📌 一言でいうと
Tenda製のルーター AC1206 および AC18 において、認証回避が可能な3つの深刻な脆弱性が公開されました。これらの脆弱性(CVE-2026-82693, CVE-2026-82694, CVE-2026-82695)はCVSSスコア10の最高評価であり、攻撃者がTelnetサービスを有効化したり、認証を回避してシステムにアクセスしたりすることが可能です。既にProof of Concept (PoC) が公開されており、迅速な対応が求められます。
🔍該当判定
- Tenda製のWi-Fiルーター『AC1206』を利用している
- Tenda製のWi-Fiルーター『AC18』を利用している
- 上記ルーターを利用しており、管理画面のパスワードを初期設定のまま(未設定)で運用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. 対象製品のファームウェアを最新バージョンに更新してください。
2. Web管理画面のパスワードを適切に設定してください。
3. 不要な管理機能(Telnet等)が有効になっていないか確認してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Tenda製ルーター 脆弱性 (CVE-2026-82693 他) 対応について
お疲れさまです。Tenda製ルーターの深刻な脆弱性に関する情報共有です。
■ 概要
Tenda AC1206 および AC18 において、認証回避が可能な脆弱性が3件報告されました。CVSS v3.x スコアは 10 (Critical) と非常に高く、攻撃者が認証を回避してTelnetサービスを有効化し、デバイスを制御できる可能性があります。既にPoCが公開されており、悪用されるリスクが高い状態です。
■ 影響範囲
- Tenda AC1206
- Tenda AC18
■ 対応手順
1. ネットワーク内で上記製品が利用されていないか資産確認を行う。
2. 利用している場合は、ベンダーが提供する最新のファームウェアへアップデートを適用する。
3. 管理者パスワードがデフォルトのまま、あるいは未設定でないか確認し、強固なパスワードを設定する。
■ 参考情報
- CSIRT-ITA Alert AL03/260901/CSIRT-ITA
対応優先度: 高
対応期限: 至急
お疲れさまです。Tenda製ルーターの深刻な脆弱性に関する情報共有です。
■ 概要
Tenda AC1206 および AC18 において、認証回避が可能な脆弱性が3件報告されました。CVSS v3.x スコアは 10 (Critical) と非常に高く、攻撃者が認証を回避してTelnetサービスを有効化し、デバイスを制御できる可能性があります。既にPoCが公開されており、悪用されるリスクが高い状態です。
■ 影響範囲
- Tenda AC1206
- Tenda AC18
■ 対応手順
1. ネットワーク内で上記製品が利用されていないか資産確認を行う。
2. 利用している場合は、ベンダーが提供する最新のファームウェアへアップデートを適用する。
3. 管理者パスワードがデフォルトのまま、あるいは未設定でないか確認し、強固なパスワードを設定する。
■ 参考情報
- CSIRT-ITA Alert AL03/260901/CSIRT-ITA
対応優先度: 高
対応期限: 至急
Subject: [Security Advisory] Tenda Router Vulnerabilities (CVE-2026-82693 et al.)
Dear IT Team,
We are sharing information regarding critical vulnerabilities identified in Tenda routers.
■ Overview
Three critical vulnerabilities (CVE-2026-82693, CVE-2026-82694, CVE-2026-82695) have been discovered in Tenda AC1206 and AC18 routers. With a CVSS v3.x score of 10.0, these flaws allow for authentication bypass, enabling attackers to activate Telnet services and gain unauthorized access. Public PoCs are currently available.
■ Affected Products
- Tenda AC1206
- Tenda AC18
■ Mitigation Steps
1. Identify if the affected devices are present within the corporate network.
2. Update the firmware to the latest version provided by the vendor.
3. Ensure that web-admin passwords are configured and not left as default or empty.
■ Reference
- CSIRT-ITA Alert AL03/260901/CSIRT-ITA
Priority: High
Deadline: Immediate
Dear IT Team,
We are sharing information regarding critical vulnerabilities identified in Tenda routers.
■ Overview
Three critical vulnerabilities (CVE-2026-82693, CVE-2026-82694, CVE-2026-82695) have been discovered in Tenda AC1206 and AC18 routers. With a CVSS v3.x score of 10.0, these flaws allow for authentication bypass, enabling attackers to activate Telnet services and gain unauthorized access. Public PoCs are currently available.
■ Affected Products
- Tenda AC1206
- Tenda AC18
■ Mitigation Steps
1. Identify if the affected devices are present within the corporate network.
2. Update the firmware to the latest version provided by the vendor.
3. Ensure that web-admin passwords are configured and not left as default or empty.
■ Reference
- CSIRT-ITA Alert AL03/260901/CSIRT-ITA
Priority: High
Deadline: Immediate