Tenda / Ac8 Firmware
62 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-4254 | Tenda AC8 HTTP Endpoint SysToolChangePwd doSystemCmd stack-based overflow | CRITICAL | 9.3 | Mar 16, 2026 |
| CVE-2026-4253 | Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection | MEDIUM | 5.1 | Mar 16, 2026 |
| CVE-2026-4252 | Tenda AC8 IPv6 check_is_ipv6 ip address for authentication | CRITICAL | 9.3 | Mar 16, 2026 |
| CVE-2026-3044 | Tenda AC8 Httpd Service UploadCfg webCgiGetUploadFile stack-based overflow | HIGH | 8.7 | Feb 23, 2026 |
| CVE-2026-2203 | Tenda AC8 Embedded Httpd Service fast_setting_wifi_set buffer overflow | HIGH | 8.7 | Feb 9, 2026 |
| CVE-2026-2202 | Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow | HIGH | 8.7 | Feb 9, 2026 |
| CVE-2025-12618 | Tenda AC8 DatabaseIniSet buffer overflow | HIGH | 8.7 | Nov 3, 2025 |
| CVE-2025-61498 | A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet. | HIGH | 7.5 | Oct 30, 2025 |
| CVE-2025-55852 | Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g. | HIGH | 7.5 | Sep 3, 2025 |
| CVE-2025-52054 | An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated… | MEDIUM | 5.3 | Aug 28, 2025 |
| CVE-2025-51089 | Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based bu… | MEDIUM | 6.5 | Jul 24, 2025 |
| CVE-2025-51088 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argument `shareSpeed` leads to stack-based… | MEDIUM | 5.3 | Jul 24, 2025 |
| CVE-2025-51087 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based… | HIGH | 8.6 | Jul 24, 2025 |
| CVE-2025-51085 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the argument `timeZone` and `timeType` leads t… | MEDIUM | 5.3 | Jul 24, 2025 |
| CVE-2025-51082 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack… | MEDIUM | 5.3 | Jul 24, 2025 |
| CVE-2025-5799 | Tenda AC8 WifiExtraSet fromSetWirelessRepeat stack-based overflow | HIGH | 8.7 | Jun 6, 2025 |
| CVE-2025-5798 | Tenda AC8 SetSysTimeCfg fromSetSysTime stack-based overflow | HIGH | 8.7 | Jun 6, 2025 |
| CVE-2025-4368 | Tenda AC8 MtuSetMacWan formGetRouterStatus buffer overflow | HIGH | 8.7 | May 6, 2025 |
| CVE-2025-29100 | Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list. | CRITICAL | 9.8 | Mar 24, 2025 |
| CVE-2025-29101 | Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function. | HIGH | 7.5 | Mar 20, 2025 |
| CVE-2025-29118 | Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878. | MEDIUM | 6.5 | Mar 19, 2025 |
| CVE-2025-1853 | Tenda AC8 Parameter SetIpMacBind sub_49E098 stack-based overflow | HIGH | 8.7 | Mar 3, 2025 |
| CVE-2025-25510 | Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function. | MEDIUM | 6.5 | Feb 21, 2025 |
| CVE-2025-25668 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function. | CRITICAL | 9.8 | Feb 20, 2025 |
| CVE-2025-25667 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info. | CRITICAL | 9.8 | Feb 20, 2025 |
Showing 1 to 25 of 62 CVEs