CVE-2026-8264Medium· 6.3▾ SunlitA weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.9%
A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
ac6_firmware = 15.03.06.23Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-8265Medium· 4.7A security vulnerability has been detected in Tenda AC6 15.03.06.23
CVE-2026-8259Medium· 4.7A vulnerability has been found in Tenda AC6 2.0/15.03.06.23
CVE-2026-86167Critical· 9.9A vulnerability was identified in Tenda HG10 300001138
CVE-2026-86152Critical· 10.0A flaw has been found in Tenda CP3 27.5.57.101
CVE-2026-86151Critical· 9.1A vulnerability was detected in Tenda CP3 27.5.57.101
CVE-2026-86149Critical· 9.1A weakness has been identified in Tenda CP3 27.5.57.101