CVE detail
CVE-2026-6024
A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.tenda.com.cn/www.tenda.com.cn
No excerpt available.
Release Noteswww.tenda.com.cnApr 10, 2026, 6:16 AM - https://vuldb.com/vuln/356600/ctivuldb.com
No excerpt available.
Exploitvuldb.comApr 10, 2026, 6:16 AM - https://vuldb.com/vuln/356600vuldb.com
No excerpt available.
Exploitvuldb.comApr 10, 2026, 6:16 AM - https://vuldb.com/submit/791826vuldb.com
No excerpt available.
Exploitvuldb.comApr 10, 2026, 6:16 AM No excerpt available.
Exploitgithub.comApr 10, 2026, 6:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- Litengzheng/vuldb_newHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 19, 2026, 12:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-0993CVSS 7.2 · High
A vulnerability was found in Tenda i6 1.0.0.9(3857). It has been classified as critical. Affected is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the…
- CVE-2024-0992CVSS 7.2 · High
A vulnerability was found in Tenda i6 1.0.0.9(3857) and classified as critical. This issue affects the function formwrlSSIDset of the file /goform/wifiSSIDset of the component htt…
- CVE-2024-0991CVSS 7.2 · High
A vulnerability has been found in Tenda i6 1.0.0.9(3857) and classified as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm of the component…
- CVE-2024-0990CVSS 7.2 · High
A vulnerability, which was classified as critical, was found in Tenda i6 1.0.0.9(3857). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component…
- CVE-2023-48964CVSS 7.5 · High
Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/WifiMacFilterSet.
- CVE-2023-48963CVSS 7.5 · High
Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/wifiSSIDget.