Impact
The vulnerability resides in the R7WebsSecurityHandler function of the Tenda AC1206 web interface, where manipulation of the /goform/ate endpoint removes required authentication checks. This allows an attacker to perform unauthenticated actions, potentially altering device configuration, disabling services, or enabling further lateral movement. The flaw is an authentication bypass, which directly compromises confidentiality, integrity, and availability of the affected router.
Affected Systems
The affected product is the Tenda AC1206 router, specifically firmware version 15.03.06.23. No other firmware versions were identified as impacted by this vulnerability.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. Although an EPSS score is not available, the exploit is publicly available and can be launched remotely, which implies a high likelihood of real‑world attacks. The vulnerability is not yet listed in the CISA KEV catalog, but the absence of KEV status does not reduce the risk posed by a publicly known authentication bypass.
OpenCVE Enrichment