High severity7.3NVD Advisory· Published Apr 9, 2026· Updated Apr 30, 2026
CVE-2026-5841
CVE-2026-5841
Description
A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Affected products
1- cpe:2.3:o:tenda:i3_firmware:1.0.0.6\(2204\):*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/MrXiaoFan/TendaVul/tree/main/tenda-i3-V1.0.0.6(2204)-R7WebsSecurityHandler-Authentication%20Bypass%20IssuesnvdExploitThird Party Advisory
- vuldb.com/submit/789935nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/356297nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/356297/ctinvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.