CVE-2026-8263
published 2026-05-11CVE-2026-8263: A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of…
PriorityP274critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.55%
90.5th percentile
A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ac10u_firmware | — | — |
| tenda | ac6 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.0LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.8MEDIUMAV:N/AC:L/Au:M/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-49r7-qrrc-gw83: A security flaw has been discovered in Tenda AC6 15
ghsa_unreviewed·2026-05-11
CVE-2026-8263 [LOW] CWE-77 GHSA-49r7-qrrc-gw83: A security flaw has been discovered in Tenda AC6 15
A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
VulDB
Tenda AC6 15.03.06.49_multi_TDE01 httpd /goform/WifiExtraSet fromSetWirelessRepeat mac/ssid os command injection
vuldb·2026-05-10
CVE-2026-8263 [CRITICAL] Tenda AC6 15.03.06.49_multi_TDE01 httpd /goform/WifiExtraSet fromSetWirelessRepeat mac/ssid os command injection
A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection.
This vulnerability is cataloged as CVE-2026-8263. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-8263 mozjs115: prettier parseNestedCSS ReDoS [fedora-42]
bugzilla·2025-07-28
CVE-2025-8263 [MEDIUM] CVE-2025-8263 mozjs115: prettier parseNestedCSS ReDoS [fedora-42]
CVE-2025-8263 mozjs115: prettier parseNestedCSS ReDoS [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases
Bugzilla
CVE-2025-8263 thunderbird: prettier parseNestedCSS ReDoS [fedora-42]
bugzilla·2025-07-28
CVE-2025-8263 [MEDIUM] CVE-2025-8263 thunderbird: prettier parseNestedCSS ReDoS [fedora-42]
CVE-2025-8263 thunderbird: prettier parseNestedCSS ReDoS [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releas
Bugzilla
CVE-2025-8263 js-d3-flame-graph: prettier parseNestedCSS ReDoS [fedora-42]
bugzilla·2025-07-28
CVE-2025-8263 [MEDIUM] CVE-2025-8263 js-d3-flame-graph: prettier parseNestedCSS ReDoS [fedora-42]
CVE-2025-8263 js-d3-flame-graph: prettier parseNestedCSS ReDoS [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-8263 h3: prettier parseNestedCSS ReDoS [fedora-42]
bugzilla·2025-07-28
CVE-2025-8263 [MEDIUM] CVE-2025-8263 h3: prettier parseNestedCSS ReDoS [fedora-42]
CVE-2025-8263 h3: prettier parseNestedCSS ReDoS [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that a
Bugzilla
CVE-2025-8263 grafana: prettier parseNestedCSS ReDoS [fedora-42]
bugzilla·2025-07-28
CVE-2025-8263 [MEDIUM] CVE-2025-8263 grafana: prettier parseNestedCSS ReDoS [fedora-42]
CVE-2025-8263 grafana: prettier parseNestedCSS ReDoS [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases t
2026-05-11
Published