Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-4254

Опубликовано: 16 мар. 2026
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local_2c causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:tenda:ac8_firmware:*:*:*:*:*:*:*:*
Версия до 16.03.50.11 (включая)
cpe:2.3:h:tenda:ac8:5.0:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00154
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-119
CWE-787

Связанные уязвимости

CVSS3: 9.8
github
25 дней назад

A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local_2c causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

EPSS

Процентиль: 36%
0.00154
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-119
CWE-787