CVE-2026-2202: Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow
A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2202?
CVE-2026-2202 is classified as a high-severity vulnerability due to its potential to allow remote code execution through buffer overflow.
How do I fix CVE-2026-2202?
To fix CVE-2026-2202, you should update the Tenda AC8 firmware to the latest version provided by Tenda, which addresses this vulnerability.
What software is affected by CVE-2026-2202?
CVE-2026-2202 specifically affects the Tenda AC8 router running firmware version 16.03.33.05.
What type of vulnerability is CVE-2026-2202?
CVE-2026-2202 is a buffer overflow vulnerability that occurs within the httpd component of the Tenda AC8 router.
Can CVE-2026-2202 be exploited remotely?
Yes, CVE-2026-2202 can be exploited remotely if an attacker manipulates the shareSpeed argument in the WifiGuestSet function.