CVE-2026-7036

A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
References
Link Resource
https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_80/README.md Exploit Third Party Advisory
https://vuldb.com/submit/798479 Third Party Advisory VDB Entry
https://vuldb.com/vuln/359616 Third Party Advisory VDB Entry
https://vuldb.com/vuln/359616/cti Permissions Required VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:i9_firmware:1.0.0.5\(2204\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:i9:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-26 12:16

Updated : 2026-06-17 11:01


NVD link : CVE-2026-7036

Mitre link : CVE-2026-7036

CVE.ORG link : CVE-2026-7036


JSON object : View

Products Affected

tenda

  • i9
  • i9_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')