A missing-authentication flaw in the Tenda AC1206 router's web UI lets a remote, unauthenticated attacker reach the /goform/ate endpoint, and a public exploit is already circulating.
What Is It
CVE-2026-82694 is a missing authentication vulnerability in Tenda AC1206 firmware 15.03.06.23. The issue lives in the R7WebsSecurityHandler function handling the /goform/ate file within the router's Web UI component. Manipulation of this path results in missing authentication, and the attack can be initiated remotely.
The CVE is tracked under CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function), and was assigned by VulDB ([email protected]). It was published on 2026-08-31 and currently carries a NVD status of "Received."
Why It Matters
The CVSS v3.1 base score is 10.0 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, no privileges, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. CVSS v4.0 scores it 9.3 (CRITICAL) and, notably, sets exploit maturity to PROOF_OF_CONCEPT. CVSS v2.0 also rates it 10.0 with complete C/I/A impact.
Per the NVD description, "the exploit is publicly available and might be used." A write-up of the issue is hosted on GitHub. No source consulted for this brief confirms in-the-wild exploitation, and CISA KEV status was not verified here; defenders should check the KEV catalog directly. Regardless of catalog status, a public PoC against an unauthenticated, network-reachable endpoint on a consumer router narrows the gap considerably.
What's Vulnerable
- Vendor: Tenda
- Product: AC1206
- Affected version: firmware 15.03.06.23 (status: affected)
- CPE:
cpe:2.3:o:tenda:ac1206_firmware:*:*:*:*:*:*:*:* - Component/module: Web UI, specifically
/goform/ateviaR7WebsSecurityHandler
Patch Status
The supplied source material does not list a vendor patch, fixed version, or advisory, and it does not include CISA KEV data for CVE-2026-82694; so no KEV due date or required action can be stated from these sources. Defenders should confirm current KEV status independently and consult the vendor directly at tenda.com.cn for remediation guidance.
Sources
- NVD, CVE-2026-82694: https://nvd.nist.gov/vuln/detail/CVE-2026-82694
- VulDB, CVE-2026-82694: https://vuldb.com/cve/CVE-2026-82694
- VulDB, Vulnerability 397182: https://vuldb.com/vuln/397182
- VulDB, CTI details: https://vuldb.com/vuln/397182/cti
- VulDB, Submission 894241: https://vuldb.com/submit/894241
- GitHub; TENDA-AC1206-ATE-DEFAULT-UNAUTH-002 write-up: https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TENDA-AC1206-ATE-DEFAULT-UNAUTH-002-vulndb.md
- Tenda: https://www.tenda.com.cn/