CVE-2026-8263Medium· 4.7▾ SunlitA security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.6%
A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
ac10u_firmware = 15.03.06.49_multi_tde01Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-8265Medium· 4.7A security vulnerability has been detected in Tenda AC6 15.03.06.23
CVE-2026-8264Medium· 6.3A weakness has been identified in Tenda AC6 15.03.06.23
CVE-2026-8259Medium· 4.7A vulnerability has been found in Tenda AC6 2.0/15.03.06.23
CVE-2026-86167Critical· 9.9A vulnerability was identified in Tenda HG10 300001138
CVE-2026-86152Critical· 10.0A flaw has been found in Tenda CP3 27.5.57.101
CVE-2026-86151Critical· 9.1A vulnerability was detected in Tenda CP3 27.5.57.101