CVE-2026-4252

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
References
Link Resource
https://github.com/digitalandrew/tenda_ac8_v5/blob/main/poc_ipv6_auth_bypass.py Exploit
https://vuldb.com/?ctiid.351210 Permissions Required VDB Entry
https://vuldb.com/?id.351210 Third Party Advisory VDB Entry
https://vuldb.com/?submit.771759 Exploit Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac8_firmware:16.03.50.11:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac8:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-16 17:16

Updated : 2026-06-17 10:56


NVD link : CVE-2026-4252

Mitre link : CVE-2026-4252

CVE.ORG link : CVE-2026-4252


JSON object : View

Products Affected

tenda

  • ac8
  • ac8_firmware
CWE
CWE-287

Improper Authentication

CWE-291

Reliance on IP Address for Authentication