Cyber & AI intelligence
Wasteland.
Briefs indexed2348
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82694 2026-08-31

Tenda AC1206: Unauthenticated Access to /goform/ate (CVE-2026-82694)

"A missing-authentication flaw in the Tenda AC1206 router's web UI lets a remote, unauthenticated attacker reach the `/goform/ate` endpoint, and a public exploit is already circulating."

A missing-authentication flaw in the Tenda AC1206 router's web UI lets a remote, unauthenticated attacker reach the /goform/ate endpoint, and a public exploit is already circulating.

What Is It

CVE-2026-82694 is a missing authentication vulnerability in Tenda AC1206 firmware 15.03.06.23. The issue lives in the R7WebsSecurityHandler function handling the /goform/ate file within the router's Web UI component. Manipulation of this path results in missing authentication, and the attack can be initiated remotely.

The CVE is tracked under CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function), and was assigned by VulDB ([email protected]). It was published on 2026-08-31 and currently carries a NVD status of "Received."

Why It Matters

The CVSS v3.1 base score is 10.0 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, no privileges, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. CVSS v4.0 scores it 9.3 (CRITICAL) and, notably, sets exploit maturity to PROOF_OF_CONCEPT. CVSS v2.0 also rates it 10.0 with complete C/I/A impact.

Per the NVD description, "the exploit is publicly available and might be used." A write-up of the issue is hosted on GitHub. No source consulted for this brief confirms in-the-wild exploitation, and CISA KEV status was not verified here; defenders should check the KEV catalog directly. Regardless of catalog status, a public PoC against an unauthenticated, network-reachable endpoint on a consumer router narrows the gap considerably.

What's Vulnerable

Patch Status

The supplied source material does not list a vendor patch, fixed version, or advisory, and it does not include CISA KEV data for CVE-2026-82694; so no KEV due date or required action can be stated from these sources. Defenders should confirm current KEV status independently and consult the vendor directly at tenda.com.cn for remediation guidance.

Sources