CVE-2026-4252Patch(tenda / ac8)

MEDIUMCVSS 8.9 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch tenda ac8 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-287CWE-291

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac8
  • ac8_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
ac8ac8_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-16: 4PoC Mentioned / Linked · 2026-03-16: 1Exploit Tool / Code · 2026-03-16: 1Patch / Workaround · 2026-03-16: 2Technical Details · 2026-03-16: 303-16
Signal classification3 categories
Patch
250.0%
General
125.0%
PoC
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4252 — CVSS 9.8/10 ██████████ A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/HZzGsWVTCs

    Post summary

    The tweet announces CVE‑2026‑4252 as a critical flaw in the Tenda AC8 firmware, identifies the vulnerable function, and urges users to apply the available patch.

    1000029
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4252 Tenda AC8 Remote Authentication Bypass via IPv6 Handler Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4252

    Post summary

    The post merely references CVE-2026-4252 with a link to additional details, providing no deeper technical or operational information.

    0000053
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-4252: CRITICAL] Critical security alert! Vulnerability found in Tenda AC8 16.03.50.11 allows remote attacks by exploiting the IPv6 Handler component. Stay secure and update now!#cve,CVE-2026-4252,#cybersecurity https://cvefind.com/CVE-2026-4252

    Post summary

    The alert announces a critical vulnerability (CVE‑2026‑4252) in Tenda AC8 that allows remote attacks through the IPv6 Handler component, urging users to apply updates.

    0000063
    601 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-4252: Tenda AC8 IPv6 check_is_ipv6 ip a... IPv6 spoofing bypasses auth on 50+ million Tenda routers - trivial remote exploitation with public PoC makes this a botn... https://zerodaysignal.com/vulnerability/CVE-2026-4252 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-4252 enables IPv6 spoofing to bypass authentication on millions of Tenda routers, with a public PoC demonstrating trivial remote exploitation and potential for large‑scale impact.

    00000103
    151 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac8---
OStendaac8_firmware16.03.50.11--

Explore more