CVE-2026-5526
7.3Tenda · 4G03 Pro
A remote improper access control vulnerability exists in the Tenda 4G03 Pro router within the /bin/httpd component, potentially allowing unauthorized access.
Executive summary
The Tenda 4G03 Pro router is susceptible to a remote improper access control vulnerability that could allow unauthorized actors to manipulate system functionality.
Vulnerability
This vulnerability involves improper access controls and incorrect privilege assignment within the /bin/httpd binary, which can be triggered remotely by an unauthenticated attacker.
Business impact
The exploitation of this vulnerability poses a significant risk to network integrity and confidentiality, as it enables remote attackers to bypass access restrictions on the device. With a CVSS score of 7.3, this flaw is categorized as High severity, indicating that unauthorized parties could potentially gain control over router settings or expose sensitive internal network traffic. Failure to address this could lead to full compromise of the edge device and unauthorized access to the local area network.
Remediation
Immediate Action: Check the official Tenda support website for firmware updates addressing this flaw and apply them to all affected units immediately.
Proactive Monitoring: Monitor firewall logs and router management access attempts for suspicious traffic patterns originating from unauthorized external IP addresses.
Compensating Controls: Restrict management interface access to trusted administrative IP addresses only, and disable remote web-based management features if they are not strictly required for business operations.
Exploitation status
Public Exploit Available: Yes — per the CVE record, the exploit has been released to the public.
Analyst recommendation
Given the remote exploitability and the confirmed availability of public exploit code, this vulnerability represents a high risk to the security of the internal network. Administrators should prioritize identifying all affected Tenda 4G03 Pro devices and applying the latest available security patches as soon as they are provided by the vendor. In environments where patching is delayed, isolating the management interface from the public internet is essential to prevent unauthorized access.
More Tenda CVEs
Sources
Originally found and disclosed by CoreNode (VulDB User), with VulDB Vulnerability Moderation Team (coordinator), per the CVE Program record.
- VDB-355279 | Tenda 4G03 Pro httpd access control Vulnerability database entry
- VDB-355279 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #782052 | Tenda Tenda 4G03 Pro V1.0 V04.03.01.53 Authentication Bypass Issues Third-party advisory
- tenda.com.cn