A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published and may be used.
https://vuldb.com/vuln/399464/cti
https://vuldb.com/submit/906608
https://vuldb.com/submit/906607
https://vuldb.com/submit/906606
https://vuldb.com/cve/CVE-2026-86300
https://github.com/limou89/somevul/blob/main/Tenda_AC9_getProduct_Info_Disclosure.md
https://github.com/limou89/somevul/blob/main/Tenda_AC9_fast_setting_wifi_set_Unauth_Password.md
Published: 2026-09-07
Updated: 2026-09-08
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 7.3
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity: High
Base Score: 6.9
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Severity: Medium
EPSS: 0.00488