VYPR

AC1200 Router

by Tenda

CVEs (10)

  • CVE-2025-45429CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.01

    In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.

  • CVE-2022-42058CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2022-42053HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.

  • CVE-2022-41396HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.

  • CVE-2022-41395HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.

  • CVE-2022-40847HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerability allows attackers to run arbitrary commands on the server via the hostname parameter.

  • CVE-2022-42060HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2022-40845MedNov 15, 2022
    risk 0.42cvss 6.5epss 0.01

    The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information…

  • CVE-2022-40844MedNov 15, 2022
    risk 0.35cvss 5.4epss 0.01

    In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL body.

  • CVE-2022-40846MedNov 15, 2022
    risk 0.31cvss 4.8epss 0.01

    In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.