Description
A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published and may be used.
Published: 2026-09-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Tenda AC9 firmware 15.03.05.14 and allows an attacker to bypass authentication in the R7WebsSecurityHandler component of the web management interface. This flaw can grant unauthorized control over the router, enabling configuration changes, firmware manipulation, or network egress for further attacks.

Affected Systems

Tenda AC9 routers running firmware version 15.03.05.14. The flaw is limited to this specific firmware release and the R7WebsSecurityHandler function within the web management module.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity overall. Since the attack vector is remote and the exploit is publicly published, an attacker could target the router over the internet. While the EPSS score is not available, the lack of listing in the KEV catalog does not diminish the risk of local or network administrators exploiting the device. Consequently, organizations should treat this issue as a high priority for remediation.

Generated by OpenCVE AI on September 7, 2026 at 13:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to the latest firmware version issued by Tenda that fixes the R7WebsSecurityHandler authentication bug
  • Restrict external access to the router’s web management interface, for example by disabling remote management or blocking management ports from non‑trusted networks
  • Configure a strong, unique administrator password and enable any available two‑factor authentication for web access

Generated by OpenCVE AI on September 7, 2026 at 13:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda ac9
Vendors & Products Tenda ac9

Mon, 07 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published and may be used.
Title Tenda AC9 Web Management R7WebsSecurityHandler improper authentication
First Time appeared Tenda
Tenda ac9 Firmware
Weaknesses CWE-287
CPEs cpe:2.3:o:tenda:ac9_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda ac9 Firmware
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-07T11:30:09.363Z

Reserved: 2026-09-06T16:33:21.215Z

Link: CVE-2026-86300

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T12:17:21.520

Modified: 2026-09-07T12:17:21.520

Link: CVE-2026-86300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T13:30:16Z

Weaknesses