Sceawere
Vulnerability Detail
CVE-2026-86300UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tenda AC9 Improper Authentication Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 2h ago
- Vendor
- Tenda
- Product
- AC9
- Attack Type
- Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-07T12:17:21.520Z",
"pubdate": "2026-09-07T12:17:21.520Z",
"executiveSummary": "This vulnerability involves an improper authentication flaw within the Tenda AC9 router, specifically targeting the Web Management interface.\nThe vulnerability resides within the R7WebsSecurityHandler function, allowing for unauthorized manipulation of authentication processes.\nThis flaw is remotely exploitable, meaning an attacker does not require physical access to the device to initiate an attack.\nSuccessful exploitation allows an attacker to bypass intended authentication mechanisms, potentially granting unauthorized access to the device management interface.\nGiven that public exploit code is available, the risk to affected devices is high, as the barrier to entry for potential attackers is significantly lowered.\nImpact includes total compromise of device settings, modification of network configurations, or potential lateral movement within the local network through the compromised gateway.",
"technicalDetails": "The vulnerability is located in the Web Management component of Tenda AC9 firmware version 15.03.05.14.\nThe specific root cause is an implementation error within the R7WebsSecurityHandler function, which is responsible for mediating authentication requests and session management for the web-based administrative interface.\nThe flaw stems from improper validation of authentication credentials or session tokens, allowing the function to be coerced into bypassing the standard security checks.\nWhen a remote attacker sends a specifically crafted HTTP request to the device, the R7WebsSecurityHandler fails to enforce appropriate authentication logic. This manipulation of the security handler allows the attacker to reach privileged administrative functions without providing legitimate credentials.\nThe attack flow proceeds as follows: First, the attacker identifies the target Tenda AC9 device exposed to the network. Second, the attacker crafts a malicious request targeted at the administrative web service, specifically designed to trigger the vulnerable R7WebsSecurityHandler logic in a way that bypasses authentication verification.\nUpon receiving the request, the R7WebsSecurityHandler fails to authenticate the session correctly, transitioning the attacker to an authenticated state within the web management interface.\nOnce this authentication bypass is achieved, the attacker gains full control over the router's configuration panel. This allows the execution of administrative commands, such as changing DNS settings to facilitate man-in-the-middle attacks, modifying firewall rules to open further internal access, or dumping sensitive device configuration data.\nBecause the vulnerability exists in the core security handler of the management interface, it is highly critical, as it effectively renders the device's login security controls void against remote actors who know how to interface with the vulnerable handler."
}