CVE-2026-7036
קריטית 9.8
תיאור (מקור, אנגלית)
A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
5.5 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-26/9/2026
- CWE
- CWE-22
מוצרים מושפעים
tenda: i9 firmware; tenda: i9
קישורים
- https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_80/README.md ExploitThird Party Advisory
- https://vuldb.com/submit/798479 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359616 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359616/cti Permissions RequiredVDB Entry
- https://www.tenda.com.cn/ Product