A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
References
| Link | Resource |
|---|---|
| https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_84/README.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/791826 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/356600 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/356600/cti | Permissions Required VDB Entry |
| https://www.tenda.com.cn/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
30 Apr 2026, 13:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Tenda
Tenda i6 Tenda i6 Firmware |
|
| CPE | cpe:2.3:o:tenda:i6_firmware:1.0.0.7\(2204\):*:*:*:*:*:*:* cpe:2.3:h:tenda:i6:-:*:*:*:*:*:*:* |
|
| References | () https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_84/README.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/791826 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/356600 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/356600/cti - Permissions Required, VDB Entry | |
| References | () https://www.tenda.com.cn/ - Product |
10 Apr 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-10 06:16
Updated : 2026-06-17 11:00
NVD link : CVE-2026-6024
Mitre link : CVE-2026-6024
CVE.ORG link : CVE-2026-6024
JSON object : View
Products Affected
tenda
- i6_firmware
- i6
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
