Junglewise Threat Intelligence

CVE-2026-8259: Tenda AC6 OS command injection in /goform/telnet

CVE-2026-8259 · Severity: medium · CVSS 4.7 · Published 2026-05-11

Technologies: Tenda Ac6 Firmware, Tenda AC6. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda AC6 wireless router, a device used to provide Wi-Fi connectivity in homes and small offices. An attacker with administrative access can exploit this flaw to execute unauthorized system commands on the router. This could lead to a complete takeover of the device, allowing the attacker to intercept network traffic, change security settings, or use the router as a foothold for further attacks on the local network.

Technical details

An OS command injection vulnerability exists in the TendaTelnet handler (0x45b860) within the /bin/httpd binary of Tenda AC6 V2.0 firmware V15.03.06.23. The application fails to sanitize the 'lan.ip' parameter received via the /goform/telnet endpoint before passing it to a system() call via doSystemCmd(). Specifically, the input is formatted into a 'telnetd -b %s &' string, allowing an attacker to use shell metacharacters (e.g., semicolons) to execute arbitrary commands. While remote exploitation is possible, it requires high privileges (administrative session) to access the vulnerable web form. A public proof-of-concept exists demonstrating the ability to read sensitive files like /etc/passwd.

Affected products

  • Tenda AC6 2.0/15.03.06.23

Timeline

  • 2026-05-11: disclosed: Initial disclosure and NVD publication
  • 2026-05-11: advisory

References

Related threats