Impact
A flaw in the Tenda AC8 router’s web interface allows an attacker to manipulate the wans.policy.list1 argument of the /cgi-bin/UploadCfg endpoint, triggering an operating‑system command injection. The vulnerability falls under the weaknesses listed as CWE‑77 and CWE‑78. This allows an attacker to execute arbitrary commands on the device, potentially leading to full system compromise.
Affected Systems
Affected systems are Tenda AC8 routers running firmware version 16.03.50.11. Earlier firmware releases such as the generic 5.0 line are not confirmed to be vulnerable according to the information available. The insecure route_set_user_policy_rule function resides in the web interface component of the 16.03.50.11 build.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score is 8 %. The issue is not listed in the CISA KEV catalog. The official description states that the attack can be launched remotely without authentication, and public proof‑of‑concept code is available, suggesting that exploitation is feasible and could occur from external networks. Based on the description, it is inferred that successful exploitation may grant an attacker complete control over the device’s configuration and operations.
OpenCVE Enrichment