Tenda AC8 Calculated Root Password Vulnerability Allowing Unauthorized Access

Vulnerability

A vulnerability exists in the Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router, specifically in the firmware version 16.03.33.05 and earlier. The issue arises because the root password is generated using a static string combined with the last two octets of the device's MAC address. This predictable password generation allows an unauthenticated attacker to gain administrative access by authenticating with network services on the device.

Impact

Exploitation of this vulnerability allows for unauthorized authentication as the root user, potentially leading to full administrative access on the device. This could include executing arbitrary commands or accessing the physical UART interface.

Remediation

Tenda has not provided any firmware updates for this router since February 2023, and the product is no longer supported. Users are advised to replace the device with a currently supported model. As a temporary measure, remote access services such as Telnet and SSH should be disabled.

Added: Aug 28, 2025, 3:22 PM
Updated: Aug 28, 2025, 3:22 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
8.4
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.