Sploitus

CVE-2026-8264

No indexed exploits for CVE-2026-8264 yet

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

Affected products
Ac6
Tenda ac6 Firmware
= 15.03.06.23
CVSS 3.1
8.8 HIGH
EPSS
2.9% (86th percentile)
Weakness
CWE-77, CWE-78
NVD status
Analyzed
Published
2026-05-11
CVE-2026-8264 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-8264 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-8264 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.