← Vulnerability feed

Vulnerability record · CVE-2026-4252 · published 16 March 2026

CVE-2026-4252: Tenda ac8 firmware improper authentication vulnerability

Tenda · Ac8 Firmware

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

8.9 CVSS 4.0 High EPSS 2.0% · top 20.3% CWE-287 · Improper authenticationCWE-291 · CWE-291
8.9CVSS 4.0 base score, v2 10.0
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-4252 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-29100Tenda ac8 firmware stack-based buffer overflow vulnerabilityTenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.EPSS 0.62%9.8CVE-2025-25663Tenda ac8 firmware out-of-bounds write vulnerabilityA vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of th…EPSS 0.55%9.8CVE-2025-25664Tenda ac8 firmware out-of-bounds write vulnerabilityTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.EPSS 0.55%9.8CVE-2025-25667Tenda ac8 firmware classic buffer overflow vulnerabilityTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.EPSS 0.57%9.8CVE-2025-25668Tenda ac8 firmware classic buffer overflow vulnerabilityTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.EPSS 0.55%9.8CVE-2024-57703Tenda ac8 firmware out-of-bounds write vulnerabilityTenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSche…EPSS 0.56%9.8CVE-2024-46652Tenda ac8 firmware out-of-bounds write vulnerabilityTenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.EPSS 0.57%9.8CVE-2023-48194Tenda ac8 firmware out-of-bounds write vulnerabilityVulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2026-4252), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.