Tongyu AX1800 Wi-Fi 6 Router Authentication Bypass Vulnerability Allowing Arbitrary Configuration Changes

Vulnerability

An authentication bypass vulnerability has been identified in the Tongyu AX1800 Wi-Fi 6 Router running firmware 1.0.0. This vulnerability allows unauthenticated, network-adjacent attackers to make arbitrary configuration changes without credentials, provided a valid admin session is active. Exploitation of this vulnerability could lead to a full compromise of the device, as it allows unauthenticated access to critical administrative endpoints.

Impact

Exploitation of this vulnerability could result in unauthorized access to the router's administrative functions, allowing attackers to make changes to the device's configuration. This could lead to a complete compromise of the router, including potential denial-of-service conditions or unauthorized access to sensitive information.

Reproduction

An unauthenticated attacker on the local network can access the router's administrative endpoints, such as '/boaform/formSaveConfig', and perform privileged operations. This can be done without valid session cookies, as long as a user has previously logged in and the session is still active.

Added: Jan 13, 2026, 5:26 PM
Updated: Jan 13, 2026, 5:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
2.0
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.