CVE-2026-8264Disclosure(tenda / ac6)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac6
  • ac6_firmware

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
ac6ac6_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-11: 2Technical Details · 2026-05-11: 205-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-8264 A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component h… https://www.cve.org/CVERecord?id=CVE-2026-8264

    Post summary

    The text announces a vulnerability in a Tenda AC6 device, describing the affected function, but provides no PoC, exploit detail, patch, or evidence of active exploitation.

    00000149
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8264 OS Command Injection in Tenda AC6 15.03.06.23 WifiApScan Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8264

    Post summary

    The post announces CVE‑2026‑8264 as an OS Command Injection vulnerability affecting Tenda AC6's WifiApScan function, with no additional exploit or mitigation details provided.

    0000075
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac62.0--
OStendaac6_firmware15.03.06.23--

Explore more