Tenda AC6 Command Injection Vulnerability in formWifiApScan Function

Vulnerability

A command injection vulnerability has been identified in the Tenda AC6 V2.0 router, specifically in the firmware version 15.03.06.23. The issue arises in the formWifiApScan function of the httpd component, where the 'wl2g.public.country' and 'wl5g.public.country' parameters are processed without proper input validation. This flaw allows remote attackers to inject and execute arbitrary operating system commands.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the device's operating system.

Reproduction

To reproduce this vulnerability, send a POST request to '/goform/WifiApScan' with a valid session cookie. Include the 'wl2g.public.country' or 'wl5g.public.country' parameter with a payload that injects a command, such as 'id'.

Added: May 11, 2026, 4:20 AM
Updated: May 11, 2026, 4:20 AM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
4.8
remediation
0.0
relevance
7.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.