CVE-2026-4254
CRITICALTenda AC8 HTTP Endpoint SysToolChangePwd doSystemCmd stack-based overflow
Title source: cnaDescription
A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local_2c causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Scores
CVSS v3
9.8
EPSS
0.0023
EPSS Percentile
45.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-119
CWE-787
CWE-121
Status
published
Products (13)
Tenda/AC8
16.03.50.0
Tenda/AC8
16.03.50.1
Tenda/AC8
16.03.50.10
Tenda/AC8
16.03.50.11
Tenda/AC8
16.03.50.2
Tenda/AC8
16.03.50.3
Tenda/AC8
16.03.50.4
Tenda/AC8
16.03.50.5
Tenda/AC8
16.03.50.6
Tenda/AC8
16.03.50.7
... and 3 more
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026