Executive brief
A security vulnerability exists in the Tenda AC6 wireless router, a device used to provide Wi-Fi connectivity in homes and small offices. An attacker with administrative access can exploit this flaw to run unauthorized system commands on the router. This could lead to a complete takeover of the device, allowing the attacker to monitor network traffic, disrupt internet service, or use the router as a foothold for further attacks on the local network.
Technical details
An OS command injection vulnerability exists in the 'get_log_file' function (offset 0x4462d0) within the '/bin/httpd' binary of Tenda AC6 V2.0 (AC1206) firmware version 15.03.06.23. The vulnerability is located in the handling of the '/goform/getLogFile' endpoint. The application retrieves the 'wans.flag' POST parameter using 'websGetVar()' and improperly incorporates it into a system call via 'doSystemCmd()' using a format string like 'echo "%s:" >> <logfile>'. An attacker can escape the double-quote context using shell metacharacters (e.g., '";id;"') to execute arbitrary OS commands. While the attack is reachable over the network, it requires high privileges (valid administrative session).
Affected products
- Tenda AC6 (AC1206) 15.03.06.23
Timeline
- 2026-05-11: disclosed: Public disclosure of the vulnerability and PoC
- 2026-05-11: advisory: NVD publication date