CVE-2026-3044Disclosure(tenda / ac8)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch tenda ac8 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. The manipulation of the argument boundary leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac8
  • ac8_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 8 classified signals
  • Peaked 3d ago at 4 mentions (2026-02-24); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
ac8ac8_firmware

2 versions affected across 2 products

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-02-23: 2Mentions · 2026-02-24: 4Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1PoC Mentioned / Linked · 2026-02-23: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 4Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2302-2402-2702-2803-01
Signal classification2 categories
Disclosure
888.9%
PoC
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-232
Disclosure1PoC1
2026-02-244
Disclosure4
2026-02-271
Disclosure1
2026-02-281
Disclosure1
2026-03-011
Disclosure1
Full discourse9 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3044 (CVSS:7.4, HIGH) is Analyzed. A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-..https://nvd.nist.gov/vuln/detail/CVE-2026-3044 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3044, a high‑severity vulnerability in Tenda AC8 affecting the webCgiGetUploadFile function, with CVSS 7.4, but provides no PoC, exploit, or patch details.

    0000021
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3044 (CVSS:7.4, HIGH) is Analyzed. A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-..https://nvd.nist.gov/vuln/detail/CVE-2026-3044 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces discovery of CVE-2026-3044 in Tenda AC8, detailing the affected function and CVSS severity, but does not provide exploit, patch, or mitigation information.

    0000026
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3044 (CVSS:7.4, HIGH) is Analyzed. A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-..https://nvd.nist.gov/vuln/detail/CVE-2026-3044 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3044, detailing its high CVSS score and the specific vulnerable function in Tenda AC8 firmware, but does not provide any PoC, exploit, or patch information.

    0000028
    173 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 HIGH severity alert: Tenda AC8 routers (16.03.34.06) face a public buffer overflow exploit via /cgi-bin/UploadCfg. Patch unavailable — restrict access & monitor traffic! 🔒 Details: https://radar.offseq.com/threat/cve-2026-3044-stack-based-buffer-overflow-in-tenda-c3428cc0 #O... https://t.co/qKIaxmJMxL

    Post summary

    High severity buffer overflow vulnerability in Tenda AC8 routers; no patch available, recommend restricting access and monitoring traffic.

    0000052
    269 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3044 A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. Th… https://www.cve.org/CVERecord?id=CVE-2026-3044

    Post summary

    A vulnerability (CVE-2026-3044) was identified in Tenda AC8 firmware affecting the webCgiGetUploadFile function in the Httpd Service, with technical details provided but no PoC, exploit, or patch information.

    00000170
    56.5K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3044 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3044 #CVE-2026-3044 #CVE #High #CyberSecurity #InfoSec https://t.co/Odd1EcAeTp

    Post summary

    A new CVE-2026-3044 with severity 8.8 has been announced, affecting multiple unspecified products, but no PoC, exploit, patch, or active exploitation details are provided.

    0000058
    57 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-3044** pertains to a **stack-based buffer overflow** vulnerability found in the Tenda AC8 router firmware version **16.03.34.06**. The flaw resides specifically within the `webCgiGetUploadFile` function located in the `/cgi-bin/UploadCfg` endpoint of the HTTP daemon (`Httpd` service). This vulnerability allows an attacker to remotely execute arbitrary code or cause a denial of service (DoS) by exploiting improper handling of input boundaries during file upload operations. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS #BufferOverflow https://cvetodo.com/cve/CVE-2026-3044

    Post summary

    The post discloses a stack‑based buffer overflow in Tenda AC8 firmware that permits remote code execution or denial of service, but it does not mention any PoC, exploit, patch, or active exploitation.

    0000058
    20 followersView on X
  • CVEFind.com@CveFindCom
    PoC

    [CVE-2026-3044: HIGH] Critical vulnerability identified in Tenda AC8 16.03.34.06's Httpd Service allows remote stack-based buffer overflow attacks via webCgiGetUploadFile. Be vigilant as exploit is now public.#cve,CVE-2026-3044,#cybersecurity https://cvefind.com/CVE-2026-3044

    Post summary

    A critical stack-based buffer overflow vulnerability in Tenda AC8's Httpd Service (CVE-2026-3044) has been disclosed, with a public exploit now available, but no patch or active exploitation details are provided.

    0000076
    584 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Tenda AC8 (CVE-2026-3044) https://vuldb.com/?id.347400

    Post summary

    A new vulnerability, CVE-2026-3044, affecting the Tenda AC8 router has been added to a vulnerability database.

    0000082
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac8---
OStendaac8_firmware16.03.34.06--

Explore more