CVE detail
CVE-2026-4252
A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.tenda.com.cn/www.tenda.com.cn
No excerpt available.
Third Party Advisorywww.tenda.com.cnMar 16, 2026, 5:16 PM - https://vuldb.com/?submit.771759vuldb.com
No excerpt available.
Exploitvuldb.comMar 16, 2026, 5:16 PM - https://vuldb.com/?id.351210vuldb.com
No excerpt available.
Exploitvuldb.comMar 16, 2026, 5:16 PM - https://vuldb.com/?ctiid.351210vuldb.com
No excerpt available.
Exploitvuldb.comMar 16, 2026, 5:16 PM No excerpt available.
Exploitgithub.comMar 16, 2026, 5:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- digitalandrew/tenda_ac8_v5High confidencegithubNVD Exploit reference0 starsDiscovered Jul 14, 2026, 6:20 AM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-52054CVSS 5.3 · Medium
An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string…
- CVE-2023-7211CVSS 5.6 · Medium
A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipu…
- CVE-2026-4254CVSS 8.9 · High
A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpo…
- CVE-2026-4253CVSS 2.0 · Low
A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of the component Web Interface. T…
- CVE-2026-3044CVSS 7.4 · High
A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. The manipulat…
- CVE-2026-2203CVSS 7.4 · High
A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Http…