Medium severity4.7NVD Advisory· Published May 11, 2026· Updated May 12, 2026
CVE-2026-8263
CVE-2026-8263
Description
A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/yaoyue123/iot/blob/main/Tenda/AC10U/fromSetWirelessRepeat.mdnvdExploitThird Party Advisory
- vuldb.com/submit/810074nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/362560nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/362560/ctinvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.