CVE 5.1 MEDIUM

Tenda AC6 httpd getLogFile get_log_file os command injection_CVE-2026-8265

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

Basic Information

ID CVE-2026-8265
Source VulDB
Published May 11, 2026 at 02:30

Affected Product

Vendor Tenda
Product AC6
Version 15.03.06.23
Affected Versions Tenda AC6 15.03.06.23

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.