Vulnerability Description
A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | I9 Firmware | 1.0.0.5\(2204\) |
| Tenda | I9 | - |
Related Weaknesses (CWE)
References
- https://github.com/Litengzheng/vuldb_new/blob/main/M3/vul_80/README.mdExploitThird Party Advisory
- https://vuldb.com/submit/798479Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359616Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359616/ctiPermissions RequiredVDB Entry
- https://www.tenda.com.cn/Product
FAQ
What is CVE-2026-7036?
CVE-2026-7036 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal....
How severe is CVE-2026-7036?
CVE-2026-7036 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7036?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda I9 Firmware, Tenda I9.