HIGH
Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow
Published Feb 9, 2026
8.7
HIGHCVSS 4.0
EPSS 0.78%
Description
A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
Affected products
-
- Version 16.03.33.05StatusaffectedConstraints-
- Version
AND
- 16.03.33.05
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/AC8/WifiGuestSet-sharespeed-bufferoverflow.md relatedExploitThird Party Advisory
- https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/AC8/WifiGuestSet-sharespeed-bufferoverflow.md#poc exploitThird Party Advisory
- https://vuldb.com/?ctiid.344905 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.344905 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.750225 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.tenda.com.cn/ product
| Link | Providers | Tags |
|---|---|---|
| https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/AC8/WifiGuestSet-sharespeed-bufferoverflow.md | relatedExploitThird Party Advisory | |
| https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/AC8/WifiGuestSet-sharespeed-bufferoverflow.md#poc | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.344905 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.344905 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.750225 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.tenda.com.cn/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Feb 9, 2026
Updated Feb 23, 2026
Reserved Feb 7, 2026
Link CVE-2026-2202
CISA Vulnrichment
Updated Feb 9, 2026