CVE-2026-8259: Tenda AC6 httpd telnet os command injection
A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8259?
CVE-2026-8259 is classified as a high severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2026-8259?
To fix CVE-2026-8259, update the Tenda AC6 firmware to the latest patched version provided by Tenda.
What type of attack can exploit CVE-2026-8259?
CVE-2026-8259 can be exploited through OS command injection attacks by manipulating the 'lan.ip' argument.
Which software versions are impacted by CVE-2026-8259?
CVE-2026-8259 affects Tenda AC6 version 2.0/15.03.06.23.
Can CVE-2026-8259 be exploited remotely?
Yes, CVE-2026-8259 can be exploited remotely, allowing unauthorized users to execute commands on the affected system.