Junglewise Threat Intelligence

CVE-2026-6024: Tenda i6 auth bypass via path traversal in HTTP Handler

CVE-2026-6024 · Severity: high · CVSS 7.3 · Published 2026-04-10

Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda i6 wireless access point that allows unauthorized individuals to bypass the login screen. By sending a specially crafted web request, an attacker can gain full administrative access to the device's management interface. This could allow an attacker to change network settings, intercept traffic, or perform unauthorized system upgrades without needing a password.

Technical details

A path traversal vulnerability exists in the 'httpd' component of Tenda i6 firmware version 1.0.0.7(2204). The 'R7WebsSecurityHandlerfunction' implements a security whitelist for unauthenticated access to static resources (e.g., /public/) using 'strncmp' to validate URL prefixes. However, the function fails to canonicalize the URL before processing. An unauthenticated remote attacker can use directory traversal sequences (e.g., '/public/../') to bypass the authentication check and access sensitive administrative pages like 'system_upgrade.asp'. This results in a complete authentication bypass and full administrative control over the device.

Affected products

  • Tenda i6 1.0.0.7(2204)

Timeline

  • 2026-04-10: advisory: Initial disclosure by VulDB
  • 2026-04-10: disclosed: Public disclosure of the exploit details

References