PT-2026-25746 · Tenda · Ac8+1

Digitalandrew

·

Published

2026-03-16

·

Updated

2026-03-17

·

CVE-2026-4254

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC8 versions through 16.03.50.11
Description A weakness exists in the Tenda AC8. This issue affects the doSystemCmd function within the /goform/SysToolChangePwd file of the HTTP Endpoint component. Manipulation of the local 2c argument leads to a stack-based buffer overflow. The attack can be initiated remotely. A public exploit is available.
Recommendations Versions through 16.03.50.11 should be updated to a newer, fixed version when available. As a temporary workaround, consider restricting access to the /goform/SysToolChangePwd file or disabling the doSystemCmd function until a patch is available.

Exploit

Fix

DoS

Stack Overflow

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-4254

Affected Products

Ac8
Ac8 Firmware