CVE-2026-4252

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
References
Link Resource
https://github.com/digitalandrew/tenda_ac8_v5/blob/main/poc_ipv6_auth_bypass.py Exploit
https://vuldb.com/?ctiid.351210 Permissions Required VDB Entry
https://vuldb.com/?id.351210 Third Party Advisory VDB Entry
https://vuldb.com/?submit.771759 Exploit Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac8_firmware:16.03.50.11:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac8:-:*:*:*:*:*:*:*

History

03 Apr 2026, 19:39

Type Values Removed Values Added
First Time Tenda
Tenda ac8
Tenda ac8 Firmware
CPE cpe:2.3:h:tenda:ac8:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac8_firmware:16.03.50.11:*:*:*:*:*:*:*
References () https://github.com/digitalandrew/tenda_ac8_v5/blob/main/poc_ipv6_auth_bypass.py - () https://github.com/digitalandrew/tenda_ac8_v5/blob/main/poc_ipv6_auth_bypass.py - Exploit
References () https://vuldb.com/?ctiid.351210 - () https://vuldb.com/?ctiid.351210 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.351210 - () https://vuldb.com/?id.351210 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.771759 - () https://vuldb.com/?submit.771759 - Exploit, Third Party Advisory, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
Summary
  • (es) Una vulnerabilidad fue identificada en Tenda AC8 16.03.50.11. Afectada por este problema es la función check_is_ipv6 del componente Gestor IPv6. La manipulación conduce a la dependencia de la dirección IP para la autenticación. Es posible iniciar el ataque remotamente. El exploit está disponible públicamente y podría ser utilizado.

16 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 17:16

Updated : 2026-04-03 19:39


NVD link : CVE-2026-4252

Mitre link : CVE-2026-4252

CVE.ORG link : CVE-2026-4252


JSON object : View

Products Affected

tenda

  • ac8
  • ac8_firmware
CWE
CWE-287

Improper Authentication

CWE-291

Reliance on IP Address for Authentication