PT-2026-2498 · Tongyu · Tongyu Ax1800 Wi-Fi 6 Router
Published
2026-01-13
·
Updated
2026-02-13
·
CVE-2025-68707
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tongyu AX1800 Wi-Fi 6 Router version 1.0.0
Description
An authentication bypass exists in the Tongyu AX1800 Wi-Fi 6 Router firmware. This allows unauthenticated attackers on the same network to make arbitrary configuration changes without valid credentials, provided a valid admin session is active. Successful exploitation can lead to a full compromise of the device through unauthenticated access to the
/boaform/formSaveConfig and /boaform/admin API endpoints.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict network access to the router's management interface.
Exploit
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tongyu Ax1800 Wi-Fi 6 Router