Tenda
Tenda AC8 Firmware: vulnerabilidades y CVE
Tenda AC8 Firmware tiene 62 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 27 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE62
Últimos 12 meses8
Críticas27
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-4254 | Alta (8.9) | 1.3% | — | 16 mar 2026 | A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument… |
| CVE-2026-4253 | Baja (2) | 8.2% | — | 16 mar 2026 | A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of the component Web Interface. The manipulation of the argument… |
| CVE-2026-4252 | Alta (8.9) | 2.0% | — | 16 mar 2026 | A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is… |
| CVE-2026-3044 | Alta (7.4) | 0.96% | — | 24 feb 2026 | A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. The manipulation of the argument boundary leads to… |
| CVE-2026-2203 | Alta (7.4) | 0.78% | — | 9 feb 2026 | A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This manipulation of the… |
| CVE-2026-2202 | Alta (7.4) | 0.78% | — | 9 feb 2026 | A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in… |
| CVE-2025-12618 | Alta (7.4) | 5.0% | — | 3 nov 2025 | A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated… |
| CVE-2025-61498 | Alta (7.5) | 0.38% | — | 30 oct 2025 | A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet. |
| CVE-2025-55852 | Alta (7.5) | 0.40% | — | 3 sept 2025 | Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g. |
| CVE-2025-52054 | Media (5.3) | 0.32% | — | 28 ago 2025 | An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC… |
| CVE-2025-51089 | Media (6.5) | 6.8% | — | 24 jul 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow. |
| CVE-2025-51088 | Media (5.3) | 6.7% | — | 24 jul 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argument `shareSpeed` leads to stack-based buffer overflow. |
| CVE-2025-51087 | Alta (8.6) | 10% | — | 24 jul 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow. |
| CVE-2025-51085 | Media (5.3) | 6.7% | — | 24 jul 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the argument `timeZone` and `timeType` leads to stack-based buffer overflow. |
| CVE-2025-51082 | Media (5.3) | 0.42% | — | 24 jul 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack-based buffer overflow. |
| CVE-2025-5799 | Alta (7.4) | 1.2% | — | 6 jun 2025 | A vulnerability was found in Tenda AC8 16.03.34.09. It has been declared as critical. Affected by this vulnerability is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the… |
| CVE-2025-5798 | Alta (7.4) | 1.2% | — | 6 jun 2025 | A vulnerability was found in Tenda AC8 16.03.34.09. It has been classified as critical. Affected is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument timeType leads to… |
| CVE-2025-4368 | Alta (8.7) | 0.90% | — | 6 may 2025 | A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetRouterStatus of the file /goform/MtuSetMacWan. The manipulation of the argument shareSpeed leads to… |
| CVE-2025-29100 | Crítica (9.8) | 0.62% | — | 24 mar 2025 | Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list. |
| CVE-2025-29101 | Alta (7.5) | 0.47% | — | 20 mar 2025 | Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function. |
| CVE-2025-29118 | Media (6.5) | 0.34% | — | 19 mar 2025 | Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878. |
| CVE-2025-1853 | Alta (8.7) | 1.5% | — | 3 mar 2025 | A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E098 of the file /goform/SetIpMacBind of the component Parameter Handler. The manipulation of the… |
| CVE-2025-25510 | Media (6.5) | 0.30% | — | 21 feb 2025 | Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function. |
| CVE-2025-25668 | Crítica (9.8) | 0.55% | — | 20 feb 2025 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function. |
| CVE-2025-25667 | Crítica (9.8) | 0.57% | — | 20 feb 2025 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info. |
| CVE-2025-25664 | Crítica (9.8) | 0.55% | — | 20 feb 2025 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function. |
| CVE-2025-25663 | Crítica (9.8) | 0.55% | — | 20 feb 2025 | A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. |
| CVE-2025-0528 | Alta (8.6) | 5.9% | — | 17 ene 2025 | A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request… |
| CVE-2024-57704 | Alta (8.8) | 0.40% | — | 16 ene 2025 | Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime leads to… |
| CVE-2024-57703 | Crítica (9.8) | 0.56% | — | 16 ene 2025 | Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.