A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
References
| Link | Resource |
|---|---|
| https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/Tenda%20AC6V2%20formWifiApScan%20Command%20Injection%20via%20country%20parameter.md | Exploit Third Party Advisory |
| https://vuldb.com/submit/810075 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362561 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/362561/cti | Permissions Required VDB Entry |
| https://www.tenda.com.cn/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
11 May 2026, 17:04
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/Tenda%20AC6V2%20formWifiApScan%20Command%20Injection%20via%20country%20parameter.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/810075 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/362561 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/362561/cti - Permissions Required, VDB Entry | |
| References | () https://www.tenda.com.cn/ - Product | |
| CPE | cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac6_firmware:15.03.06.23:*:*:*:*:*:*:* |
|
| First Time |
Tenda ac6
Tenda ac6 Firmware Tenda |
11 May 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 04:16
Updated : 2026-05-11 17:04
NVD link : CVE-2026-8264
Mitre link : CVE-2026-8264
CVE.ORG link : CVE-2026-8264
JSON object : View
Products Affected
tenda
- ac6_firmware
- ac6
