← Terug naar overzicht

A missing authentication vulnerability was identified in Tenda AC1206 firmware version 15.03.06.23. The flaw exists in the R7WebsSecurityHandler function within the /goform/ate endpoint of the device's Web UI component. An unauthenticated remote attacker can exploit this vulnerability without any credentials. The attack vector is network-based and requires no user interaction. A public exploit is already available, increasing the risk of active exploitation. This type of vulnerability in consumer and SOHO routers poses significant risks to network security. The affected product is a widely used wireless router from the Chinese manufacturer Tenda. The availability of a public proof-of-concept makes immediate patching or mitigation highly advisable.

Affected products

  • Tenda AC1206 15.03.06.23

Related CVE's

  • CVE-2026-82694

Categories

  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure