Impact
The vulnerability resides in Tenda AC9 firmware 15.03.05.14 and allows an attacker to bypass authentication in the R7WebsSecurityHandler component of the web management interface. This flaw can grant unauthorized control over the router, enabling configuration changes, firmware manipulation, or network egress for further attacks.
Affected Systems
Tenda AC9 routers running firmware version 15.03.05.14. The flaw is limited to this specific firmware release and the R7WebsSecurityHandler function within the web management module.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity overall. Since the attack vector is remote and the exploit is publicly published, an attacker could target the router over the internet. While the EPSS score is not available, the lack of listing in the KEV catalog does not diminish the risk of local or network administrators exploiting the device. Consequently, organizations should treat this issue as a high priority for remediation.
OpenCVE Enrichment