← Vulnerability feed

Vulnerability record · CVE-2025-51087 · published 24 July 2025

CVE-2025-51087: Tenda ac8 firmware stack-based buffer overflow vulnerability

Tenda · Ac8 Firmware

Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.

8.6 CVSS 3.1 High EPSS 10% · top 4.5% CWE-121 · Stack-based buffer overflow
8.6CVSS 3.1 base score
10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
5 Jul 2026Last modified by NVD

Description

Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-51087 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-29100Tenda ac8 firmware stack-based buffer overflow vulnerabilityTenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.EPSS 0.62%9.8CVE-2025-25663Tenda ac8 firmware out-of-bounds write vulnerabilityA vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of th…EPSS 0.55%9.8CVE-2025-25664Tenda ac8 firmware out-of-bounds write vulnerabilityTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.EPSS 0.55%9.8CVE-2025-25667Tenda ac8 firmware classic buffer overflow vulnerabilityTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.EPSS 0.57%9.8CVE-2025-25668Tenda ac8 firmware classic buffer overflow vulnerabilityTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.EPSS 0.55%9.8CVE-2024-57703Tenda ac8 firmware out-of-bounds write vulnerabilityTenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSche…EPSS 0.56%9.8CVE-2024-46652Tenda ac8 firmware out-of-bounds write vulnerabilityTenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.EPSS 0.57%9.8CVE-2023-48194Tenda ac8 firmware out-of-bounds write vulnerabilityVulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2025-51087), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.