CVE-2026-2202Disclosure(tenda / ac8)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac8
  • ac8_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-09)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ac8ac8_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-08: 1Mentions · 2026-02-09: 2PoC Mentioned / Linked · 2026-02-09: 1Technical Details · 2026-02-09: 202-0802-09
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-081
Disclosure1
2026-02-092
Disclosure1Exploit1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2202 A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manip… https://www.cve.org/CVERecord?id=CVE-2026-2202

    Post summary

    A vulnerability has been identified in Tenda AC8 firmware, affecting the fromSetWifiGusetBasic function in the httpd component. No proof‑of‑concept, exploitation details, or patches are provided.

    00010210
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-2202: HIGH] Critical security alert: Vulnerability in Tenda AC8 16.03.33.05 allows remote buffer overflow with public exploit available. Immediate action recommended. #cybersecurity#cve,CVE-2026-2202,#cybersecurity https://cvefind.com/CVE-2026-2202

    Post summary

    The alert highlights a critical remote buffer overflow in Tenda AC8 firmware, noting that a public exploit exists but offers no patch, detailed exploit code, or evidence of active attacks.

    0000082
    583 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Tenda AC8 (CVE-2026-2202) https://vuldb.com/?id.344905

    Post summary

    A new vulnerability (CVE-2026-2202) affecting the Tenda AC8 was added to a vulnerability database, with no further technical details, exploitation evidence, or mitigation information provided.

    0000068
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac8---
OStendaac8_firmware16.03.33.05--

Explore more