CVE-2026-82694
CRITICAL(10.0)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- CVSS 10 — Kritisch
EPSS-Score
1.4%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
10
Technische Schwere
SecBoard-Einordnung
Die Schwachstelle CVE-2026-82694 betrifft die Tenda AC1206 Firmware-Version 15.03.06.23. Es handelt sich um eine fehlende Authentifizierung in der Funktion R7WebsSecurityHandler der Komponente Web UI, die eine Remote-Ausnutzung ermöglicht. Ein Angreifer kann dadurch unautorisierten Zugriff erlangen.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.