CVE-2026-6024

A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
References
Link Resource
https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_84/README.md Exploit Third Party Advisory
https://vuldb.com/submit/791826 Third Party Advisory VDB Entry
https://vuldb.com/vuln/356600 Third Party Advisory VDB Entry
https://vuldb.com/vuln/356600/cti Permissions Required VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:i6_firmware:1.0.0.7\(2204\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:i6:-:*:*:*:*:*:*:*

History

30 Apr 2026, 13:54

Type Values Removed Values Added
First Time Tenda
Tenda i6
Tenda i6 Firmware
CPE cpe:2.3:o:tenda:i6_firmware:1.0.0.7\(2204\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:i6:-:*:*:*:*:*:*:*
References () https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_84/README.md - () https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_84/README.md - Exploit, Third Party Advisory
References () https://vuldb.com/submit/791826 - () https://vuldb.com/submit/791826 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/356600 - () https://vuldb.com/vuln/356600 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/356600/cti - () https://vuldb.com/vuln/356600/cti - Permissions Required, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product

10 Apr 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-10 06:16

Updated : 2026-06-17 11:00


NVD link : CVE-2026-6024

Mitre link : CVE-2026-6024

CVE.ORG link : CVE-2026-6024


JSON object : View

Products Affected

tenda

  • i6_firmware
  • i6
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')