CVE-2026-7036

A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
References
Link Resource
https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_80/README.md Exploit Third Party Advisory
https://vuldb.com/submit/798479 Third Party Advisory VDB Entry
https://vuldb.com/vuln/359616 Third Party Advisory VDB Entry
https://vuldb.com/vuln/359616/cti Permissions Required VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:i9_firmware:1.0.0.5\(2204\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:i9:-:*:*:*:*:*:*:*

History

30 Apr 2026, 14:10

Type Values Removed Values Added
First Time Tenda
Tenda i9 Firmware
Tenda i9
CPE cpe:2.3:h:tenda:i9:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:i9_firmware:1.0.0.5\(2204\):*:*:*:*:*:*:*
References () https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_80/README.md - () https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_80/README.md - Exploit, Third Party Advisory
References () https://vuldb.com/submit/798479 - () https://vuldb.com/submit/798479 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/359616 - () https://vuldb.com/vuln/359616 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/359616/cti - () https://vuldb.com/vuln/359616/cti - Permissions Required, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product

26 Apr 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-26 12:16

Updated : 2026-06-17 11:01


NVD link : CVE-2026-7036

Mitre link : CVE-2026-7036

CVE.ORG link : CVE-2026-7036


JSON object : View

Products Affected

tenda

  • i9_firmware
  • i9
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')