📦 Ac8 Firmware

by Tenda

🔍 What is Ac8 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-29100

CRITICAL CVSS 9.8 Mar 24, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8 routers via a buffer overflow in the fromSetRouteStatic function. Attackers can exploit this by sending specially craf...

CVE-2025-25664

CRITICAL CVSS 9.8 Feb 20, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8V4 routers by exploiting a stack overflow in the shareSpeed parameter. Attackers can gain full control of affected devi...

CVE-2025-25668

CRITICAL CVSS 9.8 Feb 20, 2025

This CVE describes a stack overflow vulnerability in Tenda AC8V4 routers that allows remote code execution. Attackers can exploit the shareSpeed parameter in the sub_47D878 function to crash the devic...

CVE-2024-57703

CRITICAL CVSS 9.8 Jan 16, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8v4 routers by exploiting a stack overflow in the setSchedWifi function. Attackers can trigger this by sending specially...

CVE-2024-46652

CRITICAL CVSS 9.8 Sep 20, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8v4 routers via a stack overflow in the fromAdvSetMacMtuWan function. Attackers can gain full control of affected device...

CVE-2023-48194

CRITICAL CVSS 9.8 Jul 9, 2024

This vulnerability in Tenda AC8v4 routers allows remote code execution due to a buffer overflow in the set_client_qos function. Attackers can exploit this to gain full control of affected devices. Use...

CVE-2023-4744

CRITICAL CVSS 9.8 Sep 4, 2023

This critical vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formSetDeviceName function. Attackers can exploit this witho...

CVE-2023-33669

CRITICAL CVSS 9.8 Jun 2, 2023

CVE-2023-33669 is a critical stack overflow vulnerability in Tenda AC8 routers that allows remote code execution via the timeZone parameter. Attackers can exploit this to take complete control of affe...

CVE-2023-33671

CRITICAL CVSS 9.8 Jun 2, 2023

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8 routers via a stack overflow in the saveParentControlInfo function. Attackers can exploit this by sending specially cr...

CVE-2023-33673

CRITICAL CVSS 9.8 Jun 2, 2023

This vulnerability is a stack overflow in Tenda AC8 routers via the firewallEn parameter in the formSetFirewallCfg function. It allows remote attackers to execute arbitrary code or cause denial of ser...

CVE-2026-3044

HIGH CVSS 8.8 Feb 24, 2026

A stack-based buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the boundary argument in the webCgiGetUploadFile function. This affec...

CVE-2025-12618

HIGH CVSS 8.8 Nov 3, 2025

A buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the 'Time' parameter in the /goform/DatabaseIniSet endpoint. This affects users o...

CVE-2025-55852

HIGH CVSS 7.5 Sep 3, 2025

This buffer overflow vulnerability in Tenda AC8 routers allows attackers to execute arbitrary code by sending specially crafted requests to the formWifiBasicSet function. It affects users running Tend...

CVE-2025-51087

HIGH CVSS 8.6 Jul 24, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8V4 routers by exploiting a stack-based buffer overflow in the saveParentControlInfo function. Attackers can trigger thi...

CVE-2025-5798

HIGH CVSS 8.8 Jun 6, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the timeType parameter in the fromSetSysTime function. This ...

CVE-2025-29101

HIGH CVSS 7.5 Mar 20, 2025

A stack overflow vulnerability in Tenda AC8V4.0 routers allows attackers to execute arbitrary code or cause denial of service by sending specially crafted requests to the get_parentControl_list_Info f...

CVE-2025-1853

HIGH CVSS 8.8 Mar 3, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the 'list' parameter in the SetIpMacBind function. This affe...

CVE-2025-0528

HIGH CVSS 7.2 Jan 17, 2025

This critical vulnerability in Tenda AC8, AC10, and AC18 routers allows remote attackers to execute arbitrary commands via command injection in the HTTP request handler for the /goform/telnet endpoint...

CVE-2024-10130

HIGH CVSS 8.8 Oct 18, 2024

This critical vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the reboot timer configuration function. Attackers can exploit t...

CVE-2024-10123

HIGH CVSS 8.8 Oct 18, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the 'time' parameter in the compare_parentcontrol_time funct...

CVE-2024-4066

HIGH CVSS 8.8 Apr 23, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating specific parameters in the fromAdvSetMacMtuWan function. Thi...

CVE-2024-4065

HIGH CVSS 8.8 Apr 23, 2024

This critical vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the reboot timer function. Attackers can exploit this without au...

CVE-2023-39786

HIGH CVSS 7.5 Aug 21, 2023

This CVE describes a stack overflow vulnerability in Tenda AC8V4 routers via the time parameter in the sscanf function. Attackers can exploit this to execute arbitrary code or crash the device. Users ...

CVE-2023-39784

HIGH CVSS 7.5 Aug 21, 2023

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8V4 routers via a stack overflow in the save_virtualser_data function. Attackers can exploit this by sending specially c...

CVE-2025-52054

MEDIUM CVSS 5.3 Aug 28, 2025

This vulnerability allows unauthenticated attackers to calculate the root password of Tenda AC8 routers using a static algorithm based on the device's MAC address. Attackers can then authenticate to n...

CVE-2025-51082

MEDIUM CVSS 5.3 Jul 24, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC8V4 routers by exploiting a stack-based buffer overflow in the web interface's timeZone parameter. Attackers can potenti...

CVE-2025-51089

MEDIUM CVSS 6.5 Jul 24, 2025

A heap-based buffer overflow vulnerability exists in Tenda AC8V4 routers via the /goform/GetParentControlInfo endpoint when manipulating the 'mac' argument. This allows attackers to potentially execut...

CVE-2025-25510

MEDIUM CVSS 6.5 Feb 21, 2025

A buffer overflow vulnerability in Tenda AC8 routers allows attackers to execute arbitrary code or cause denial of service by sending specially crafted requests to the get_parentControl_list_Info func...

CVE-2024-10280

MEDIUM CVSS 6.5 Oct 23, 2024

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...