CVE-2025-25667: Tenda AC8 Firmware

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.

Affected products

  • Tenda AC8 Firmware: version 16.03.34.06 only

Published 2025-02-20. Last modified 2026-06-17.