CVE-2026-8265
published 2026-05-11CVE-2026-8265: A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the…
PriorityP263high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
4.41%
90.3th percentile
A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ac6 | — | — |
| tenda | ac6_firmware | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.0LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.8MEDIUMAV:N/AC:L/Au:M/C:P/I:P/A:P
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qvqp-rwfh-7f5j: A security vulnerability has been detected in Tenda AC6 15
ghsa_unreviewed·2026-05-11
CVE-2026-8265 [LOW] CWE-77 GHSA-qvqp-rwfh-7f5j: A security vulnerability has been detected in Tenda AC6 15
A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
VulDB
Tenda AC6 15.03.06.23 httpd /goform/getLogFile get_log_file wans.flag os command injection
vuldb·2026-05-10
CVE-2026-8265 [CRITICAL] Tenda AC6 15.03.06.23 httpd /goform/getLogFile get_log_file wans.flag os command injection
A vulnerability has been found in Tenda AC6 15.03.06.23 and classified as critical. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection.
This vulnerability is documented as CVE-2026-8265. The attack can be initiated remotely. Additionally, an exploit exists.
GHSA
Ray Dashboard is vulnerable to path traversal through its static file handling mechanism
ghsa·2026-03-17
CVE-2026-32981 [HIGH] CWE-22 Ray Dashboard is vulnerable to path traversal through its static file handling mechanism
Ray Dashboard is vulnerable to path traversal through its static file handling mechanism
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.
Red Hat
ray: Ray Dashboard Path Traversal Leading to Local File Disclosure
vendor_redhat·2026-03-17·CVSS 8.7
CVE-2026-32981 [HIGH] CWE-22 ray: Ray Dashboard Path Traversal Leading to Local File Disclosure
ray: Ray Dashboard Path Traversal Leading to Local File Disclosure
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.
A path traversal flaw has been identified in Ray Dashboard in the Ray Pypi package. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.
Mitigation: Mitigation for this i
No detection rules found.
No public exploits indexed.
2026-05-11
Published