CVE-2026-82694
largeMissing Authentication in Tenda AC1206 Web UI (/goform/ate) Endpoint
CVE-2026-82694 is a critical (CVSS 4.0: 9.3) missing-authentication flaw (CWE-287/CWE-306) in the Web UI of the Tenda AC1206 router running firmware 15.03.06.23. The R7WebsSecurityHandler function fails to enforce authentication on the /goform/ate endpoint, allowing a remote, unauthenticated attacker to reach the handler directly over the network with no user interaction or privileges required. Successful access bypasses credential checks on the router's web interface, with the high confidentiality, integrity, and availability impact ratings in the CVSS score indicating potential full compromise of the device. Only Tenda AC1206 units on the identified firmware version are known to be affected. The advisory reports that a public exploit exists and might be used, though no specific PoC is cataloged; the issue is not yet in CISA KEV and EPSS currently estimates a 0.7% probability of exploitation in the next 30 days.
What to do: Check the firmware version on any Tenda AC1206 in your environment; if it is running 15.03.06.23, watch Tenda's support channel for a patched release (no fixed version is specified in the available data). Until patching is possible, reduce exposure of the management web interface by disabling WAN-side/remote management and restricting admin access to trusted networks, and monitor logs for unauthenticated requests to /goform/ate.
| Tenda AC1206 | 15.03.06.23 (firmware identified as affected; other versions not specified in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.