A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
References
| Link | Resource |
|---|---|
| https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_80/README.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/798479 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/359616 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/359616/cti | Permissions Required VDB Entry |
| https://www.tenda.com.cn/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
30 Apr 2026, 14:10
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Tenda
Tenda i9 Firmware Tenda i9 |
|
| CPE | cpe:2.3:h:tenda:i9:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:i9_firmware:1.0.0.5\(2204\):*:*:*:*:*:*:* |
|
| References | () https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_80/README.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/798479 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/359616 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/359616/cti - Permissions Required, VDB Entry | |
| References | () https://www.tenda.com.cn/ - Product |
26 Apr 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-26 12:16
Updated : 2026-06-17 11:01
NVD link : CVE-2026-7036
Mitre link : CVE-2026-7036
CVE.ORG link : CVE-2026-7036
JSON object : View
Products Affected
tenda
- i9_firmware
- i9
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
