PT-2026-25785 · Tenda · Ac8

Digitalandrew

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2026-4253

CVSS v2.0
5.8
VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route set user policy rule of the file /cgi-bin/UploadCfg of the component Web Interface. The manipulation of the argument wans.policy.list1 results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4253

Affected Products

Ac8