CVE-2026-82694: Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Tenda AC1206 devices running firmware version 15.03.06.23 are identified as affected. Exposure is through the device's Web UI and its /goform/ate endpoint.
What does an attacker need to exploit it?
The issue can be exploited remotely with no authentication, user interaction, or stated special privileges required. A public exploit is available, which may lower the effort needed for attackers to target exposed devices.
Is this likely to affect a default deployment?
The available information identifies missing authentication in the Web UI handler but does not state that a configuration change is required. Devices with the affected firmware should be treated as exposed wherever the Web UI is reachable by an attacker.