Executive brief
A security vulnerability has been identified in the Tenda AC8 router, a device used to provide wireless internet connectivity. An attacker can send a specially crafted network packet to the device's UPnP service to cause it to crash or become unresponsive. This results in a denial-of-service, disrupting internet access for all connected users and requiring a manual restart of the hardware.
Technical details
A stack-based buffer overflow (CWE-121) exists in the UPnP service of Tenda AC8 hardware running firmware version v03.03.10.01. The vulnerability is triggered when the service processes a specially crafted network packet, leading to memory corruption. This is a network-reachable exploit that requires no authentication or user interaction. Successful exploitation results in a Denial of Service (DoS) condition, crashing the service or the entire device. No official patch or mitigation was detailed in the advisory, though disabling UPnP is a standard workaround for such vulnerabilities.
Affected products
- Tenda AC8 v03.03.10.01
Timeline
- 2025-10-30: disclosed
- 2025-10-30: advisory