CVE-2026-4254: Tenda AC8 HTTP Endpoint SysToolChangePwd doSystemCmd stack-based overflow
A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local2c causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4254?
CVE-2026-4254 has a high severity due to its potential for stack-based overflow vulnerabilities.
How do I fix CVE-2026-4254?
To mitigate CVE-2026-4254, update the Tenda AC8 firmware to a version later than 16.03.50.11.
What products are affected by CVE-2026-4254?
CVE-2026-4254 specifically affects the Tenda AC8 model up to version 16.03.50.11.
What is the exploit potential of CVE-2026-4254?
CVE-2026-4254 can be exploited to execute arbitrary commands on the affected device, leading to unauthorized access.
Is there a workaround for CVE-2026-4254 if a firmware update is not possible?
If a firmware update is not feasible, isolate the affected device from the network to limit exposure to the vulnerability.