An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. This allows an unauthenticated attacker to authenticate with network services on the device.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tenda ac8 Firmware
|
|
CPEs | cpe:2.3:h:tenda:ac8:4.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac8_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Tenda ac8 Firmware
|
Thu, 28 Aug 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tenda
Tenda ac8 |
|
Vendors & Products |
Tenda
Tenda ac8 |
Thu, 28 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-287 | |
Metrics |
cvssV3_1
|
Thu, 28 Aug 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. This allows an unauthenticated attacker to authenticate with network services on the device. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-28T00:00:00.000Z
Updated: 2025-08-28T20:02:23.116Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-52054

Updated: 2025-08-28T20:02:16.621Z

Status : Analyzed
Published: 2025-08-28T15:16:00.917
Modified: 2025-09-09T18:42:20.370
Link: CVE-2025-52054

No data.