Skip to content
CVSS 7.3 · HIGH

CVE-2026-7036

A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

View on NVD

Analysis

This vulnerability specifically affects the firmware of Tenda i9 wireless access points. It is vendor-specific hardware firmware that does not impact the software development stacks, server environments, or common tooling used by this community.

Severity

Score: 7.3(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: LOW
I: LOW
A: LOW
Weakness (CWE): CWE-22

EPSS

Probability of exploitation (next 30 days): 0.0024 (0.2%)
Percentile: 46.7%
EPSS: 2026-05-06

Affects

tenda:i9_firmwaretenda:i9

Technical description

A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Published: 4/26/2026, 12:16:22 PM
Last modified: 4/30/2026, 2:10:26 PM

References

HomeEventsBlogResourcesTeam