CVE-2026-4252
A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 1.26%
- CWE
- CWE-291, CWE-287
- Published
- 2026-03-16
- Last modified
- 2026-03-16
Affected products
- Tenda AC8
Weakness type
Related vulnerabilities
- CVE-2026-86485 — In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket...
- CVE-2026-3690 — OpenClaw Canvas Authentication Bypass Vulnerability
- CVE-2025-66602 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation....
- CVE-2025-59101 — Insufficient Session Management in dormakaba access manager
- CVE-2025-34202 — Vasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WAN
- CVE-2024-23309 — The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in...
- CVE-2024-32765 — QTS, QuTS hero
- CVE-2023-7211 — Uniway Router Administrative Web Interface reliance on ip address for authentication