Report: CVE-2026-8263 - Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection

Report: CVE-2026-8263 - Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection

CVE ID :CVE-2026-8263 Published : 11 May 2026, 2:16 a.m. | 15 minutes ago Description :A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Impact: command injection