5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Basic Information
ID
CVE-2026-8265
Source
VulDB
Published
May 11, 2026 at 02:30
Affected Product
Vendor
Tenda
Product
AC6
Version
15.03.06.23
Affected Versions
Tenda AC6 15.03.06.23