A vulnerability marked as critical has been reported in Tenda AC12 15.03.06.23_multi_TD01 . This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface . This manipulation of the argument rebootTime causes buffer overflow. This vulnerability appears as CVE-2026-19821 . The attack may be initiated remotely. In addition, an exploit is available.