CVE-2026-8263: Tenda AC10U Firmware

Critical severity, CVSS 9.8. EPSS: 8.7% chance of exploitation in the next 30 days.

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

Affected products

  • Tenda AC10U Firmware: version 15.03.06.49_multi_tde01 only

Published 2026-05-11. Last modified 2026-07-23.