CVE-2026-6024

CWE-22Path Traversal4 documents4 sources
Severity
6.9MEDIUM
EPSS
0.1%
top 80.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 10

Description

A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages1 packages

CVEListV5tenda/i61.0.0.7(2204)

🔴Vulnerability Details

3
CVEList
Tenda i6 HTTP R7WebsSecurityHandlerfunction path traversal2026-04-10
GHSA
GHSA-5v5f-c63q-mm7g: A vulnerability was determined in Tenda i6 12026-04-10
VulDB
Tenda i6 1.0.0.7(2204) HTTP R7WebsSecurityHandlerfunction path traversal2026-04-09