VYPR

AC1200 Router

by Tenda

CVEs (24)

  • CVE-2022-31446CriJun 14, 2022
    risk 0.66cvss 9.8epss 0.35

    Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.

  • CVE-2025-45429CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.01

    In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.

  • CVE-2023-31587CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.

  • CVE-2022-42058CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2022-40854CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set

  • CVE-2022-40860CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList

  • CVE-2022-40853CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set

  • CVE-2022-38314CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.

  • CVE-2022-38313CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.

  • CVE-2022-38312CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.

  • CVE-2022-38311CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.

  • CVE-2022-38310CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

  • CVE-2022-38309CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

  • CVE-2022-28560CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

  • CVE-2020-24987CriSep 4, 2020
    risk 0.64cvss 9.8epss 0.03

    Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authentication handling of vulnerable logincheck() function in /usr/lib/lua/ngx_authserver/ngx_wdas.lua file if the administrator UI Interface…

  • CVE-2022-42053HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.

  • CVE-2022-41396HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.

  • CVE-2022-41395HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.

  • CVE-2022-40847HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerability allows attackers to run arbitrary commands on the server via the hostname parameter.

  • CVE-2022-42060HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

Page 1 of 2