I29 Firmware
by Tenda
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-35338 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2024 | Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root. | ||
| CVE-2023-50992 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function. | ||
| CVE-2023-50990 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function. | ||
| CVE-2023-50989 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function. | ||
| CVE-2023-50988 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function. | ||
| CVE-2023-50987 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function. | ||
| CVE-2023-50986 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function. | ||
| CVE-2023-50985 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function. | ||
| CVE-2023-50984 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function. | ||
| CVE-2023-50983 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function. | ||
| CVE-2023-50991 | Hig | 0.49 | 7.5 | 0.09 | Jan 5, 2024 | Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function. |
- risk 0.64cvss 9.8epss 0.01
Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.
- risk 0.64cvss 9.8epss 0.02
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.
- risk 0.64cvss 9.8epss 0.02
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
- risk 0.49cvss 7.5epss 0.09
Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.