PT-2026-2498 · Tongyu · Tongyu Ax1800 Wi-Fi 6 Router

Publicado

2026-01-13

·

Atualizado

2026-02-13

·

CVE-2025-68707

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tongyu AX1800 Wi-Fi 6 Router version 1.0.0
Description An authentication bypass exists in the Tongyu AX1800 Wi-Fi 6 Router firmware. This allows unauthenticated attackers on the same network to make arbitrary configuration changes without valid credentials, provided a valid admin session is active. Successful exploitation can lead to a full compromise of the device through unauthenticated access to the /boaform/formSaveConfig and /boaform/admin API endpoints.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict network access to the router's management interface.

Exploit

Correção

Authentication Bypass Using an Alternate Path or Channel

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68707

Produtos afetados

Tongyu Ax1800 Wi-Fi 6 Router