CVE-2026-4961Disclosure(tenda / ac6)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for tenda ac6 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac6
  • ac6_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-28)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ac6ac6_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-27: 1Mentions · 2026-03-28: 2PoC Mentioned / Linked · 2026-03-27: 1Exploit Tool / Code · 2026-03-27: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 203-2703-28
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Exploit1
2026-03-282
Disclosure2
Full discourse3 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 Tenda AC6 Buffer Overflow CVSS: 8.8 Remote stack buffer overflow via crafted packets in Tenda AC6 router. Triggers crash or code exec, exposing home networks to unauth remote access. https://nvd.nist.gov/vuln/detail/CVE-2026-4961

    Post summary

    The post discloses a remote stack buffer overflow (CVE-2026-4961) in Tenda AC6 routers that can crash or allow unauthenticated remote code execution, rated CVSS 8.8, with no PoC, patch, or active exploitation details mentioned.

    1000053
    434 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4961 A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component P… https://www.cve.org/CVERecord?id=CVE-2026-4961

    Post summary

    The text announces CVE-2026-4961 affecting Tenda AC6, mentioning the vulnerable function and file path, but provides no PoC, exploit, or mitigation information.

    00000103
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4961: HIGH] Critical vulnerability in Tenda AC6 15.03.05.16 allows remote stack-based buffer overflow through manipulation of PPPOEPassword argument in formQuickIndex function. Public exploit availab...#cve,CVE-2026-4961,#cybersecurity https://cvefind.com/CVE-2026-4961

    Post summary

    The post announces CVE‑2026‑4961, detailing a critical stack buffer overflow in Tenda AC6 firmware and noting a public exploit is available, without mentioning active exploitation or a patch.

    0000062
    617 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac61.0--
OStendaac6_firmware15.03.05.16--

Explore more