CVE-2026-4254
- EPSS 0.15%
- Veröffentlicht 16.03.2026 17:32:11
- Zuletzt bearbeitet 20.03.2026 13:35:42
A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local_2c causes stack-based buff...
CVE-2026-4253
- EPSS 0.38%
- Veröffentlicht 16.03.2026 17:02:11
- Zuletzt bearbeitet 20.03.2026 12:55:36
A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of the component Web Interface. The manipulation of the argument wans.policy.list1 results in os command...
CVE-2026-4252
- EPSS 0.25%
- Veröffentlicht 16.03.2026 16:32:10
- Zuletzt bearbeitet 03.04.2026 19:39:21
A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack re...
CVE-2026-3044
- EPSS 0.09%
- Veröffentlicht 23.02.2026 23:32:09
- Zuletzt bearbeitet 24.02.2026 21:39:12
A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. The manipulation of the argument boundary leads to stack-based buffer overflow. It i...
CVE-2026-2203
- EPSS 0.1%
- Veröffentlicht 09.02.2026 02:02:10
- Zuletzt bearbeitet 10.02.2026 15:07:15
A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This manipulation of the argument timeZone causes buffer ove...
CVE-2026-2202
- EPSS 0.1%
- Veröffentlicht 09.02.2026 01:32:09
- Zuletzt bearbeitet 10.02.2026 15:07:30
A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be l...
CVE-2025-12618
- EPSS 0.16%
- Veröffentlicht 03.11.2025 06:32:13
- Zuletzt bearbeitet 05.11.2025 14:19:14
A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been d...
CVE-2025-61498
- EPSS 0.06%
- Veröffentlicht 30.10.2025 00:00:00
- Zuletzt bearbeitet 08.12.2025 13:14:08
A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet.
CVE-2025-55852
- EPSS 0.08%
- Veröffentlicht 03.09.2025 00:00:00
- Zuletzt bearbeitet 08.09.2025 14:03:07
Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g.
CVE-2025-52054
- EPSS 0.09%
- Veröffentlicht 28.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 18:42:20
An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. This allows ...