CVE-2026-86300
HIGHCVSS 7.3Description
A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published and may be used.
Timeline
Published:September 7th, 2026 12:17 PM
Last modified:September 8th, 2026 4:18 PM
CVSS Scoring
CVSS v3: 7.3 (HIGH)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v2: 7.5
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports
- https://github.com/limou89/somevul/blob/main/Tenda_AC9_fast_setting_wifi_set_Unauth_Password.md
- https://github.com/limou89/somevul/blob/main/Tenda_AC9_getProduct_Info_Disclosure.md
- https://vuldb.com/cve/CVE-2026-86300
- https://vuldb.com/submit/906606
- https://vuldb.com/submit/906607
- https://vuldb.com/submit/906608
- https://vuldb.com/vuln/399464
- https://vuldb.com/vuln/399464/cti
- https://www.tenda.com.cn/
- https://github.com/limou89/somevul/blob/main/Tenda_AC9_getProduct_Info_Disclosure.md
Source: NIST NVD · Data may lag official sources by up to one minute