---
id: CVE-2026-86300
title: A flaw has been found in Tenda AC9 15.03.05.14
summary: >-
  A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function
  R7WebsSecurityHandler of the component Web Management. This manipulation
  causes improper authentication. The attack may be initiated remotely. The
  exploit has been…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-287
vendor: Tenda
product: AC9
affected:
  - AC9 15.03.05.14
published: '2026-09-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T16:18:27.630'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86300'
references:
  - url: >-
      https://github.com/limou89/somevul/blob/main/Tenda_AC9_fast_setting_wifi_set_Unauth_Password.md
    label: cna@vuldb.com
  - url: >-
      https://github.com/limou89/somevul/blob/main/Tenda_AC9_getProduct_Info_Disclosure.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86300'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/906606'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/906607'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/906608'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399464'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399464/cti'
    label: cna@vuldb.com
  - url: 'https://www.tenda.com.cn/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/limou89/somevul/blob/main/Tenda_AC9_getProduct_Info_Disclosure.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T15:03:18.638512Z'
epss: 0.00843
epssPercentile: 0.56092
ingestedAt: '2026-09-08T15:33:26.976Z'
---

## Overview

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
