Junglewise Threat Intelligence

CVE-2026-86300: Tenda AC9 authentication bypass in web management

CVE-2026-86300 · Severity: high · CVSS 7.3 · Published 2026-09-07

Technologies: Tenda Ac9. Vendors: Tenda.

Executive brief

Tenda AC9 routers contain an authentication bypass flaw in the web management interface that allows unauthenticated remote attackers to change the administrator password and access sensitive device information. An attacker can exploit this vulnerability over the network without needing any valid credentials, effectively gaining full control of the affected router and disrupting network operations.

Technical details

The vulnerability resides in the R7WebsSecurityHandler function, which maintains an auth-exempt whitelist for certain endpoints. The flaw allows multiple unauthenticated requests: (1) /goform/fast_setting_wifi_set accepts a loginPwd parameter and directly commits it as the system administrator password without authentication or current-password verification, and (2) /goform/getProduct, /goform/getWanConnectStatus, and /goform/getRebootStatus leak sensitive device information. The root cause is improper string-prefix matching logic that allows whitelist bypass when endpoint paths match auth-exempt prefixes. Attack vector is network-based with no authentication required. An attacker can change the admin password remotely or enumerate device configuration. No patch information is currently available.

Affected products

  • Tenda AC9 15.03.05.14, 15.03.05.16

Timeline

  • 2026-09-07: disclosed

References

Related threats