A missing authentication vulnerability has been identified in Tenda AC1206 firmware version 15.03.06.23. The flaw exists in the TendaTelnet function located at /goform/telnet within the Web UI component. An unauthenticated remote attacker can exploit this vulnerability by manipulating the affected endpoint without requiring any credentials. The vulnerability is remotely exploitable and the exploit has been publicly disclosed, increasing the risk of active exploitation. Affected users should apply patches or mitigations as soon as they become available. The issue has been documented in VulDB and assigned CVE-2026-82693. The public disclosure of a working exploit raises the severity and urgency for remediation.