Описание
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-82694
- https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TENDA-AC1206-ATE-DEFAULT-UNAUTH-002-vulndb.md
- https://vuldb.com/cve/CVE-2026-82694
- https://vuldb.com/submit/894241
- https://vuldb.com/vuln/397182
- https://vuldb.com/vuln/397182/cti
- https://www.tenda.com.cn
Связанные уязвимости
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
Уязвимость функции R7WebsSecurityHandler() файла /goform/ate компонента Web UI микропрограммного обеспечения маршрутизаторов Tenda AC1206, позволяющая нарушителю получить полный контроль над системой