PT-2026-2498 · Tongyu · Tongyu Ax1800 Wi-Fi 6 Router

Published

2026-01-13

·

Updated

2026-02-13

·

CVE-2025-68707

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tongyu AX1800 Wi-Fi 6 Router version 1.0.0
Description An authentication bypass exists in the Tongyu AX1800 Wi-Fi 6 Router firmware. This allows unauthenticated attackers on the same network to make arbitrary configuration changes without valid credentials, provided a valid admin session is active. Successful exploitation can lead to a full compromise of the device through unauthenticated access to the /boaform/formSaveConfig and /boaform/admin API endpoints.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict network access to the router's management interface.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-68707

Affected Products

Tongyu Ax1800 Wi-Fi 6 Router