---
id: CVE-2026-8259
title: A vulnerability has been found in Tenda AC6 2.0/15.03.06.23
summary: >-
  A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected
  element is an unknown function of the file /goform/telnet of the component
  httpd. The manipulation of the argument lan.ip leads to os command injection.
  Remote exp…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-77
  - CWE-78
  - CWE-78
vendor: tenda
product: ac6_firmware
affected:
  - ac6_firmware = 15.03.06.23
published: '2026-05-11'
updated: '2026-07-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8259'
references:
  - url: >-
      https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/Tenda%20AC6V2%20TendaTelnet%20Command%20Injection.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/809877'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362556'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362556/cti'
    label: cna@vuldb.com
  - url: 'https://www.tenda.com.cn/'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.04447
epssPercentile: 0.90986
ingestedAt: '2026-07-23T20:19:18.385Z'
---

## Overview

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

## Affected

- `ac6_firmware = 15.03.06.23`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
