Description
A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Problem types
Product status
Timeline
| 2026-04-08: | Advisory disclosed |
| 2026-04-08: | VulDB entry created |
| 2026-04-08: | VulDB entry last update |
Credits
Fan95 (VulDB User)
References
vuldb.com/vuln/356297 (VDB-356297 | Tenda i3 HTTP R7WebsSecurityHandler path traversal)
vuldb.com/vuln/356297/cti (VDB-356297 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/789935 (Submit #789935 | Tenda i3 V1.0.0.6(2204) Authentication Bypass Issues)
github.com/...bsSecurityHandler-Authentication Bypass Issues
www.tenda.com.cn/