CVE-2026-4252

Severity
8.9HIGH
EPSS
0.2%
top 52.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 16

Description

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/ac816.03.50.11
NVDtenda/ac8_firmware16.03.50.11

🔴Vulnerability Details

2
GHSA
GHSA-7fp9-cvqr-rwmf: A vulnerability was identified in Tenda AC8 162026-03-16
CVEList
Tenda AC8 IPv6 check_is_ipv6 ip address for authentication2026-03-16