{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ac9-15.03.05.14/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AC9 (15.03.05.14)"],"_cs_severities":["high"],"_cs_tags":["network-security","authentication-bypass","cve-2026-86300"],"_cs_type":"advisory","_cs_vendors":["Tenda"],"content_html":"\u003cp\u003eCVE-2026-86300 is an authentication bypass vulnerability affecting Tenda AC9 routers running firmware version 15.03.05.14. The flaw resides within the R7WebsSecurityHandler function of the device's Web Management component. This vulnerability allows remote, unauthenticated attackers to manipulate security handlers, resulting in improper authentication and potential unauthorized administrative access to the router. Because publicly available exploit code exists, the risk to exposed devices is significantly elevated. Organizations utilizing these routers should prioritize mitigating exposure, as this flaw enables direct control over network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs network reconnaissance to identify accessible Tenda AC9 administrative interfaces (often exposed on port 80 or 443).\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP request targeting the Web Management component.\u003c/li\u003e\n\u003cli\u003eThe request is specifically designed to interact with the vulnerable R7WebsSecurityHandler function.\u003c/li\u003e\n\u003cli\u003eThe router fails to validate the authentication session due to improper handler logic.\u003c/li\u003e\n\u003cli\u003eThe attacker gains unauthorized administrative-level access to the router's configuration.\u003c/li\u003e\n\u003cli\u003eThe attacker may then modify network settings, redirect traffic, or disable device security features.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated, remote attackers to gain full administrative control over the affected Tenda AC9 device. This can lead to unauthorized modification of router configurations, potential interception of network traffic, and persistence within the network. Devices with the management interface exposed to the internet are at the highest risk of compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all internet-exposed Tenda AC9 devices within the network environment using asset discovery tools.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Web Management interface by ensuring it is not reachable from untrusted or public networks.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual HTTP traffic directed at the router's administrative web interface.\u003c/li\u003e\n\u003cli\u003eCheck for manufacturer-provided firmware updates that address the vulnerability and apply them immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T12:53:17Z","date_published":"2026-09-07T12:53:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-86300/","summary":"A critical authentication bypass vulnerability, CVE-2026-86300, exists in the Tenda AC9 firmware version 15.03.05.14, allowing remote attackers to circumvent security controls via the Web Management interface.","title":"Authentication Bypass in Tenda AC9 Web Management","url":"https://feed.craftedsignal.io/briefs/2026-09-07-cve-2026-86300/"}],"language":"en","title":"CraftedSignal Threat Feed - AC9 (15.03.05.14)","version":"https://jsonfeed.org/version/1.1"}