Severity
7.4HIGH
EPSS
0.1%
top 73.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 9

Description

A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/ac816.03.33.05
NVDtenda/ac8_firmware16.03.33.05

🔴Vulnerability Details

2
GHSA
GHSA-7c2w-rcv7-7qf9: A vulnerability was detected in Tenda AC8 162026-02-09
CVEList
Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow2026-02-09