Junglewise Threat Intelligence

CVE-2026-8265: Tenda AC6 OS command injection in get_log_file

CVE-2026-8265 · Severity: medium · CVSS 4.7 · Published 2026-05-11

Technologies: Tenda Ac6 Firmware, Tenda AC6. Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda AC6 wireless router, a device used to provide Wi-Fi connectivity in homes and small offices. An attacker with administrative access can exploit this flaw to run unauthorized system commands on the router. This could lead to a complete takeover of the device, allowing the attacker to monitor network traffic, disrupt internet service, or use the router as a foothold for further attacks on the local network.

Technical details

An OS command injection vulnerability exists in the 'get_log_file' function (offset 0x4462d0) within the '/bin/httpd' binary of Tenda AC6 V2.0 (AC1206) firmware version 15.03.06.23. The vulnerability is located in the handling of the '/goform/getLogFile' endpoint. The application retrieves the 'wans.flag' POST parameter using 'websGetVar()' and improperly incorporates it into a system call via 'doSystemCmd()' using a format string like 'echo "%s:" >> <logfile>'. An attacker can escape the double-quote context using shell metacharacters (e.g., '";id;"') to execute arbitrary OS commands. While the attack is reachable over the network, it requires high privileges (valid administrative session).

Affected products

  • Tenda AC6 (AC1206) 15.03.06.23

Timeline

  • 2026-05-11: disclosed: Public disclosure of the vulnerability and PoC
  • 2026-05-11: advisory: NVD publication date

References

Related threats