CVE-2026-86300 is a high-severity (CVSS 3.1 base 7.3) improper-authentication vulnerability in the Tenda AC9 router, firmware version 15.03.05.14.
What the vulnerability does
Per NVD’s description, the flaw is in R7WebsSecurityHandler, part of the router’s web management component. Manipulation of this handler results in improper authentication, and NVD’s description states the attack can be launched remotely with exploit code already published. Referenced proof-of-concept write-ups describe a related fast-setting Wi-Fi handler allowing unauthenticated password changes and an information-disclosure issue in a getProductInfo endpoint on the same device family — consistent with a broader pattern of weak authentication enforcement across this router’s web management interface, not an isolated single-endpoint bug.
What we don’t yet have
This record traces to VulDB submissions and independent proof-of-concept write-ups referenced via NVD; no CISA KEV listing or Tenda-issued advisory is present in our ingested data, so confidence is medium. No fixed firmware version is documented — check Tenda’s own support channels directly.
Why this matters
Consumer router firmware with authentication weaknesses in its web management interface is a recurring, high-value target for botnet recruitment and network-pivot attacks, precisely because these devices are frequently left with default or exposed remote-management access and rarely receive prompt firmware updates. Administrators of Tenda AC9 devices on 15.03.05.14 should disable remote/WAN-facing web management if not strictly required, regardless of patch availability.
Frequently Asked Questions
What is CVE-2026-86300? A CVSS 7.3 high-severity improper-authentication vulnerability in Tenda AC9 router firmware 15.03.05.14’s web management component.
Is exploit code available for CVE-2026-86300? Yes, per NVD’s description — public exploit code and proof-of-concept write-ups exist, though this is distinct from confirmed active exploitation.
Is CVE-2026-86300 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD) and VulDB, aggregated September 2026. See more vulnerability intelligence.