CVE-2026-7036
published 2026-04-26CVE-2026-7036: A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.54%
41.4th percentile
A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | i9 | — | — |
| tenda | i9_firmware | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9qw4-vhj6-m3pq: A vulnerability was identified in Tenda i9 1
ghsa_unreviewed·2026-04-26
CVE-2026-7036 [MEDIUM] CWE-22 GHSA-9qw4-vhj6-m3pq: A vulnerability was identified in Tenda i9 1
A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
VulDB
Tenda i9 1.0.0.5(2204) HTTP R7WebsSecurityHandlerfunction path traversal
vuldb·2026-04-25·CVSS 6.9
CVE-2026-7036 [MEDIUM] Tenda i9 1.0.0.5(2204) HTTP R7WebsSecurityHandlerfunction path traversal
A vulnerability marked as critical has been reported in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-7036. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-26
Published