Impact
A buffer overflow flaw exists in the Embedded Httpd Service of the Tenda AC8 router. The vulnerability is triggered when the timeZone argument in the /goform/fast_setting_wifi_set endpoint is supplied with an overly long payload, allowing an attacker to execute arbitrary code on the device, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects Tenda AC8 routers running firmware version 16.03.33.05. The specific endpoint /goform/fast_setting_wifi_set is responsible for the error.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability, allowing remote attackers to exploit it via standard HTTP requests. The current EPSS score of less than 1% suggests a low probability of real‑world exploitation, although an exploit has already been published and may be available for use. The vulnerability is not listed in the CISA KEV catalog, but administrators should still consider it a high‑risk issue.
OpenCVE Enrichment