Junglewise Threat Intelligence

CVE-2026-82694: Tenda AC1206 authentication bypass in Web UI

CVE-2026-82694 · Severity: critical · CVSS 10 · Published 2026-08-31

Executive brief

Tenda AC1206 is a wireless router used to provide internet connectivity in homes and small offices. A vulnerability in the Web UI allows attackers to bypass authentication and access the device's management interface remotely without valid credentials, potentially enabling unauthorized configuration changes or data theft.

Technical details

The vulnerability is an authentication bypass (missing authentication) in the R7WebsSecurityHandler function of the /goform/ate endpoint in the Web UI component. The flaw allows unauthenticated remote access to administrative functions. The attack is network-based and requires no credentials or user interaction. An attacker can exploit this to access the device's management interface and potentially modify settings, extract configuration data, or further compromise the device. Patches or updates are not mentioned in the available advisory data.

Affected products

  • Tenda AC1206 15.03.06.23

Timeline

  • 2026-08-31: disclosed

References

Related threats