VendorsTendaac84.0
Vulnerabilities

Tenda AC8 4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2023-4744
Tenda AC8 formSetDeviceName stack-based overflow
Published 2023-09-03 · Modified
10.0EPSS 0.018
CVE-2025-12618
Tenda AC8 DatabaseIniSet buffer overflow
Published 2025-11-03 · Analyzed
9.8EPSS 0.050
CVE-2023-38935
Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.
Published 2023-08-07 · Modified
9.8EPSS 0.009
CVE-2023-38937
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38931
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2024-46652
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.
Published 2024-09-20 · Analyzed
9.8EPSS 0.006
CVE-2024-57703
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow.
Published 2025-01-16 · Analyzed
9.8EPSS 0.006
CVE-2025-25663
A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.
Published 2025-02-20 · Analyzed
9.8EPSS 0.006
CVE-2025-25664
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.
Published 2025-02-20 · Analyzed
9.8EPSS 0.006
CVE-2025-5798
Tenda AC8 SetSysTimeCfg fromSetSysTime stack-based overflow
Published 2025-06-06 · Analyzed
9.0EPSS 0.012
CVE-2025-5799
Tenda AC8 WifiExtraSet fromSetWirelessRepeat stack-based overflow
Published 2025-06-06 · Analyzed
9.0EPSS 0.012
CVE-2024-10130
Tenda AC8 SetSysAutoRebbotCfg formSetRebootTimer stack-based overflow
Published 2024-10-18 · Analyzed
9.0EPSS 0.010
CVE-2024-10123
Tenda AC8 saveParentControlInfo compare_parentcontrol_time stack-based overflow
Published 2024-10-18 · Analyzed
9.0EPSS 0.010
CVE-2024-57704
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime leads to stack-based buffer overflow.
Published 2025-01-16 · Analyzed
8.8EPSS 0.004
CVE-2025-51087
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.
Published 2025-07-24 · Modified
8.6EPSS 0.093
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2025-29101
Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function.
Published 2025-03-20 · Analyzed
7.5EPSS 0.005
CVE-2025-55852
Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g.
Published 2025-09-03 · Analyzed
7.5EPSS 0.004
CVE-2025-51089
Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow.
Published 2025-07-24 · Modified
6.5EPSS 0.068
CVE-2025-51085
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the argument `timeZone` and `timeType` leads to stack-based buffer overflow.
Published 2025-07-24 · Modified
5.3EPSS 0.067
CVE-2025-51088
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argument `shareSpeed` leads to stack-based buffer overflow.
Published 2025-07-24 · Modified
5.3EPSS 0.067
CVE-2025-51082
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack-based buffer overflow.
Published 2025-07-24 · Modified
5.3EPSS 0.004
CVE-2025-52054
An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. This allows an unauthenticated attacker to authenticate with network services on the device.
Published 2025-08-28 · Analyzed
5.3EPSS 0.003