Description
A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-02-07: | Advisory disclosed |
| 2026-02-07: | VulDB entry created |
| 2026-02-10: | VulDB entry last update |
Credits
sunnyyaya (VulDB User)
References
vuldb.com/?id.344905 (VDB-344905 | Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow)
vuldb.com/?ctiid.344905 (VDB-344905 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.750225 (Submit #750225 | Tenda AC8 V16.03.33.05 Denial of Service)
github.com/.../AC8/WifiGuestSet-sharespeed-bufferoverflow.md
github.com/.../AC8/WifiGuestSet-sharespeed-bufferoverflow.md
www.tenda.com.cn/