CVE-2026-4960: Tenda AC6 Firmware

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

Affected products

  • Tenda AC6 Firmware: version 15.03.05.16 only

Published 2026-03-27. Last modified 2026-06-17.