Skip to content
Threat Feed
high advisory

Authentication Bypass in Tenda AC9 Web Management

A critical authentication bypass vulnerability, CVE-2026-86300, exists in the Tenda AC9 firmware version 15.03.05.14, allowing remote attackers to circumvent security controls via the Web Management interface.

CVE-2026-86300 is an authentication bypass vulnerability affecting Tenda AC9 routers running firmware version 15.03.05.14. The flaw resides within the R7WebsSecurityHandler function of the device's Web Management component. This vulnerability allows remote, unauthenticated attackers to manipulate security handlers, resulting in improper authentication and potential unauthorized administrative access to the router. Because publicly available exploit code exists, the risk to exposed devices is significantly elevated. Organizations utilizing these routers should prioritize mitigating exposure, as this flaw enables direct control over network infrastructure.

Attack Chain

  1. The attacker performs network reconnaissance to identify accessible Tenda AC9 administrative interfaces (often exposed on port 80 or 443).
  2. The attacker crafts a malicious HTTP request targeting the Web Management component.
  3. The request is specifically designed to interact with the vulnerable R7WebsSecurityHandler function.
  4. The router fails to validate the authentication session due to improper handler logic.
  5. The attacker gains unauthorized administrative-level access to the router's configuration.
  6. The attacker may then modify network settings, redirect traffic, or disable device security features.

Impact

Successful exploitation of this vulnerability allows unauthenticated, remote attackers to gain full administrative control over the affected Tenda AC9 device. This can lead to unauthorized modification of router configurations, potential interception of network traffic, and persistence within the network. Devices with the management interface exposed to the internet are at the highest risk of compromise.

Recommendation

Prioritized actions for security operations and IT teams:

  • Identify all internet-exposed Tenda AC9 devices within the network environment using asset discovery tools.
  • Restrict access to the Web Management interface by ensuring it is not reachable from untrusted or public networks.
  • Monitor logs for unusual HTTP traffic directed at the router's administrative web interface.
  • Check for manufacturer-provided firmware updates that address the vulnerability and apply them immediately.

Immediate actions

Restrict access to the administrative Web Management interface for Tenda AC9 devices.

IT Operations 24h

Mitigations

Review Tenda support for firmware patches correcting CVE-2026-86300.

immediate IT Operations

CVE-2026-86300