CVE-2026-82694
Received Received - Intake

Authentication Bypass in Tenda AC1206 Web UI

Vulnerability report for CVE-2026-82694, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
tenda ac1206 15.03.06.23
tenda ac1206 *
tenda f1206 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-82694 is a missing authentication vulnerability in Tenda AC1206 routers. It affects the Web UI component via the /goform/ate route, allowing remote attackers to access sensitive functions without credentials. The flaw enables unauthorized actions like device reboot, factory reset, and configuration changes.

Detection Guidance

Check if the vulnerable route /goform/ate is accessible by sending an HTTP GET request to the router's IP address followed by /goform/ate. Use tools like curl or a web browser. If the route responds or triggers actions without authentication, the vulnerability may be present.

Impact Analysis

An attacker on the local network could exploit this to cause denial of service, modify network settings, or further compromise the device. This includes rebooting, resetting to factory defaults, or altering wireless configurations, potentially disrupting network operations.

Compliance Impact

This vulnerability allows remote attackers to gain unauthorized access to network devices without authentication, potentially exposing sensitive data. For GDPR, this could lead to unauthorized data access or processing, violating confidentiality and integrity requirements. For HIPAA, it may compromise protected health information if network devices are used in healthcare environments.

Mitigation Strategies

Update the router firmware to the latest version if available. Disable access to the /goform/ate route if possible. Ensure the router is not in factory-default empty-password state. Restrict network access to trusted devices only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82694. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart