CVE-2026-4254Disclosure(tenda / ac8)

MEDIUMCVSS 8.9 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch tenda ac8 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local_2c causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac8
  • ac8_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-16); latest day: 2
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
ac8ac8_firmware

1 version affected across 2 products

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-03-16: 5Mentions · 2026-03-17: 2PoC Mentioned / Linked · 2026-03-16: 2Exploit Tool / Code · 2026-03-16: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-16: 4Technical Details · 2026-03-17: 203-1603-17
Signal classification4 categories
Disclosure
457.1%
Exploit
114.3%
Patch
114.3%
PoC
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-165
Disclosure2Exploit1Patch1PoC1
2026-03-172
Disclosure2
Full discourse7 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4254 — CVSS 9.8/10 ██████████ A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/qk7jHTjmEH

    Post summary

    A critical flaw (CVSS 9.8/10) in Tenda AC8 routers is acknowledged, with a patch available immediately.

    1000032
    7 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4254 Tenda AC8 Remote Stack Overflow Vulnerability in HTTP Endpoint Doシステムコマンド https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4254

    Post summary

    CVE-2026-4254 is a remote stack overflow vulnerability affecting the Tenda AC8 router’s HTTP endpoint.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4254 A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component… https://www.cve.org/CVERecord?id=CVE-2026-4254

    Post summary

    An identified weakness in Tenda AC8 up to version 16.03.50.11 affects the doSystemCmd function in the /goform/SysToolChangePwd component.

    00000124
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4254 - Tenda AC8 HTTP Endpoint SysToolChangePwd doSystemCmd stack-based overflow Intel Report: https://ift.tt/r0F7Y8u

    Post summary

    The post announces a new CVE‑2026‑4254 stack‑based overflow vulnerability in Tenda AC8, but does not provide PoC code, exploitation details, or patch information.

    0000041
    335 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4254: CRITICAL] Critical vulnerability identified in Tenda AC8 up to 16.03.50.11 allows remote stack-based buffer overflow via doSystemCmd function. Public exploit poses security risk.#cve,CVE-2026-4254,#cybersecurity https://cvefind.com/CVE-2026-4254

    Post summary

    CVE-2026-4254 is a critical stack-based buffer overflow in Tenda AC8 routers for which a public exploit exists, though no active exploitation or patch details are referenced.

    0000066
    601 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-4254: Tenda AC8 HTTP E... Remote stack smash in Tenda's password change endpoint with public exploit - another IoT router begging for a shell #CVE20264254 #IoTpwn. https://zerodaysignal.com/vulnerability/CVE-2026-4254 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-4254 is a remote stack‑smashing flaw in Tenda AC8 routers’ password change endpoint, with a public exploit available, but no patch or evidence of active exploitation.

    0000083
    151 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Tenda AC8 (CVE-2026-4254) https://vuldb.com/?id.351212

    Post summary

    A newly disclosed vulnerability (CVE‑2026‑4254) with increased severity affecting the Tenda AC8 was announced, but no technical details, exploitation evidence, or patch information were included.

    0000087
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac85.0--
OStendaac8_firmware---

Explore more