Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-36789 exploits multiple stack overflow vulnerabilities in the fromGstDhcpSetSer function of Tenda AC1206 routers running firmware v15.03.06.23. By crafting HTTP requests with oversized username and password parameters, attackers can overflow the stack and trigger Denial of Service conditions. This vulnerability affects organizations and individuals relying on Tenda AC1206 routers for network connectivity, particularly in small office/home office (SOHO) environments and resource-constrained deployments where patching cycles may be longer. The high CVSS score of 7.5 reflects the ease of exploitation and significant availability impact, making it a critical concern for network infrastructure security.
While this CVE currently maps to zero MITRE ATT&CK techniques, Casky's extended reasoning capabilities excel at identifying the underlying attack infrastructure and reconnaissance patterns that precede stack overflow exploitation. Practitioners using Casky would detect attack signatures related to protocol fuzzing, parameter manipulation, and abnormal HTTP request structures targeting router management interfaces. Claude's reasoning engine can correlate suspicious HTTP activity patterns—including requests with unusual payload sizes in authentication parameters—against baseline network behavior, surfacing indicators of active exploitation attempts. Security teams would observe findings flagging abnormal DHCP configuration requests, repeated failed authentication attempts with oversized credentials, and potential memory corruption indicators, enabling them to identify and isolate compromised or at-risk Tenda devices before widespread DoS impact occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-36789. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation