CVE-2023-48194: Tenda AC8 Firmware
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained.
Affected products
- Tenda AC8 Firmware: version 16.03.34.09 only
Published 2024-07-09. Last modified 2026-07-09.