VendorsTendaac8_firmwareall versions
Vulnerabilities

Tenda AC8 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

62CVEs
CVE-2026-3044
Tenda AC8 Httpd Service UploadCfg webCgiGetUploadFile stack-based overflow
Published 2026-02-23 · Analyzed
9.0EPSS 0.010
CVE-2026-2203
Tenda AC8 Embedded Httpd Service fast_setting_wifi_set buffer overflow
Published 2026-02-09 · Analyzed
9.0EPSS 0.008
CVE-2026-2202
Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow
Published 2026-02-09 · Analyzed
9.0EPSS 0.008
CVE-2024-57704
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime leads to stack-based buffer overflow.
Published 2025-01-16 · Analyzed
8.8EPSS 0.004
CVE-2025-51087
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.
Published 2025-07-24 · Modified
8.6EPSS 0.093
CVE-2025-0528
Tenda AC8/AC10/AC18 HTTP Request telnet command injection
Published 2025-01-17 · Analyzed
8.6EPSS 0.059
CVE-2023-33672
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.
Published 2023-06-02 · Modified
7.5EPSS 0.009
CVE-2023-39784
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function.
Published 2023-08-21 · Modified
7.5EPSS 0.008
CVE-2023-39785
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function.
Published 2023-08-21 · Modified
7.5EPSS 0.008
CVE-2023-39786
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function.
Published 2023-08-21 · Modified
7.5EPSS 0.008
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2025-29101
Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function.
Published 2025-03-20 · Analyzed
7.5EPSS 0.005
CVE-2025-55852
Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g.
Published 2025-09-03 · Analyzed
7.5EPSS 0.004
CVE-2025-61498
A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet.
Published 2025-10-30 · Modified
7.5EPSS 0.003
CVE-2026-4253
Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection
Published 2026-03-16 · Analyzed
7.2EPSS 0.082
CVE-2025-51089
Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow.
Published 2025-07-24 · Modified
6.5EPSS 0.068
CVE-2025-29118
Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.
Published 2025-03-19 · Analyzed
6.5EPSS 0.003
CVE-2025-25510
Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.
Published 2025-02-21 · Analyzed
6.5EPSS 0.003
CVE-2025-51088
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argument `shareSpeed` leads to stack-based buffer overflow.
Published 2025-07-24 · Modified
5.3EPSS 0.067
CVE-2025-51085
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the argument `timeZone` and `timeType` leads to stack-based buffer overflow.
Published 2025-07-24 · Modified
5.3EPSS 0.067
CVE-2025-51082
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack-based buffer overflow.
Published 2025-07-24 · Modified
5.3EPSS 0.004
CVE-2025-52054
An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. This allows an unauthenticated attacker to authenticate with network services on the device.
Published 2025-08-28 · Analyzed
5.3EPSS 0.003
← Prev2 / 2