PT-2026-25785 · Tenda · Ac8+1

Digitalandrew

·

Published

2026-03-16

·

Updated

2026-03-17

·

CVE-2026-4253

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC8 version 16.03.50.11
Description A security issue exists in Tenda AC8 version 16.03.50.11. The issue affects the route set user policy rule function within the /cgi-bin/UploadCfg file of the Web Interface component. Manipulation of the wans.policy.list1 argument can lead to operating system command injection. The attack can be launched remotely. An exploit for this issue has been publicly released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4253

Affected Products

Ac8
Ac8 Firmware