Impact
The Tenda AC8 firmware 16.03.33.05 contains a buffer overflow flaw in the fromSetWifiGusetBasic function exposed via the httpd /goform/WifiGuestSet endpoint; manipulation of the shareSpeed argument can overflow the stack and lead to arbitrary code execution if triggered remotely.
Affected Systems
The vulnerability affects Tenda AC8 routers running firmware version 16.03.33.05; no other versions are listed as affected in the provided data.
Risk and Exploitability
With a CVSS score of 8.7 the flaw is high severity; the EPSS score being less than 1% indicates a low current exploitation probability, and it is not listed in CISA’s KEV catalog. The attack can be launched from a remote host without authentication, leveraging the publicly available exploit code to potentially gain full control of the device.
OpenCVE Enrichment