A critical missing authentication vulnerability has been identified in Tenda AC1206 firmware version 15.03.06.23. The vulnerability affects the R7WebsSecurityHandler function within the /goform/ate endpoint of the device's Web UI component. An attacker can exploit this flaw remotely without requiring any authentication credentials. The exploit code is publicly available, significantly increasing the risk of active exploitation in the wild. The issue allows unauthorized access to sensitive router functions through the web interface. Tenda AC1206 is a consumer-grade wireless router, making this vulnerability potentially impactful across many home and small business networks. The vulnerability has been catalogued in VulDB and assigned CVE-2026-82694.