CVE-2026-8259Medium· 4.7▾ SunlitA vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exp…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.4%
A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
ac6_firmware = 15.03.06.23Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-8265Medium· 4.7A security vulnerability has been detected in Tenda AC6 15.03.06.23
CVE-2026-8264Medium· 6.3A weakness has been identified in Tenda AC6 15.03.06.23
CVE-2026-86167Critical· 9.9A vulnerability was identified in Tenda HG10 300001138
CVE-2026-86152Critical· 10.0A flaw has been found in Tenda CP3 27.5.57.101
CVE-2026-86151Critical· 9.1A vulnerability was detected in Tenda CP3 27.5.57.101
CVE-2026-86149Critical· 9.1A weakness has been identified in Tenda CP3 27.5.57.101