High severity8.8NVD Advisory· Published Feb 9, 2026· Updated Jun 17, 2026
CVE-2026-2203
CVE-2026-2203
Description
A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This manipulation of the argument timeZone causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:o:tenda:ac8_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:tenda:ac8_firmware:*:*:*:*:*:*:*:*range: 16.03.33.05
- cpe:2.3:o:tenda:ac8_firmware:16.03.33.05:*:*:*:*:*:*:*
- Range: 16.03.33.05
Patches
Vulnerability mechanics
References
6- github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/AC8/fastsettingwifiset-timezome.mdnvdExploitThird Party Advisory
- github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/AC8/fastsettingwifiset-timezome.mdnvdExploitThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.