A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/Tenda%20AC6V2%20TendaTelnet%20Command%20Injection.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/809877 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362556 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362556/cti | Permissions Required VDB Entry |
| https://www.tenda.com.cn/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-05-11 02:16
Updated : 2026-07-23 20:10
NVD link : CVE-2026-8259
Mitre link : CVE-2026-8259
CVE.ORG link : CVE-2026-8259
JSON object : View
Products Affected
tenda
- ac6
- ac6_firmware
