Sploitus

CVE-2026-4254

No indexed exploits for CVE-2026-4254 yet

A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local_2c causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

Affected products
Ac8, Ac8 Firmware
Tenda ac8 Firmware
≤ 16.03.50.11
Fix
Available
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
0.9% (56th percentile)
Weakness
CWE-119, CWE-787, CWE-121
NVD status
Analyzed
Published
2026-03-16
CVE-2026-4254 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-4254 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-4254 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.