A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/Tenda%20AC6V2%20TendaTelnet%20Command%20Injection.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/809877 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362556 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362556/cti | Permissions Required VDB Entry |
| https://www.tenda.com.cn/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
11 May 2026, 17:07
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/Tenda%20AC6V2%20TendaTelnet%20Command%20Injection.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/809877 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/362556 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/362556/cti - Permissions Required, VDB Entry | |
| References | () https://www.tenda.com.cn/ - Product | |
| First Time |
Tenda ac6
Tenda ac6 Firmware Tenda |
|
| CPE | cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac6_firmware:15.03.06.23:*:*:*:*:*:*:* |
11 May 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 02:16
Updated : 2026-05-11 17:07
NVD link : CVE-2026-8259
Mitre link : CVE-2026-8259
CVE.ORG link : CVE-2026-8259
JSON object : View
Products Affected
tenda
- ac6_firmware
- ac6
