CVE-2026-86300 PUBLISHED

Tenda AC9 Web Management R7WebsSecurityHandler improper authentication

Assigner: VulDB
Reserved: 06.09.2026 Published: 07.09.2026 Updated: 07.09.2026

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published and may be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor Tenda
Product AC9
Versions
  • Version 15.03.05.14 is affected

Credits

  • sleep (VulDB User) reporter

References

Problem Types

  • Improper Authentication CWE