Medium severity4.7NVD Advisory· Published May 11, 2026· Updated May 11, 2026
CVE-2026-8259
CVE-2026-8259
Description
A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected products
1- cpe:2.3:o:tenda:ac6_firmware:15.03.06.23:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/Tenda%20AC6V2%20TendaTelnet%20Command%20Injection.mdnvdExploitThird Party Advisory
- vuldb.com/submit/809877nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/362556nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/362556/ctinvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.