VYPR

Ax12 Firmware

by Tenda

CVEs (26)

  • CVE-2024-28383CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.

  • CVE-2023-49437CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

  • CVE-2023-49428CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.03

    Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

  • CVE-2023-49426CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

  • CVE-2023-49425CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .

  • CVE-2023-49424CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

  • CVE-2022-28082CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.

  • CVE-2022-28561CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.10

    There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

  • CVE-2022-45980HigDec 12, 2022
    risk 0.58cvss 8.8epss 0.07

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .

  • CVE-2023-47422HigFeb 20, 2024
    risk 0.57cvss 8.8epss 0.00

    An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.

  • CVE-2022-45977HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.02

    Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.

  • CVE-2022-45043HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.02

    Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.

  • CVE-2024-39963HigJul 19, 2024
    risk 0.52cvss 8.0epss 0.02

    AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.

  • CVE-2021-45392HigFeb 14, 2022
    risk 0.50cvss 7.5epss 0.12

    A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service.

  • CVE-2023-49427HigJan 10, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.

  • CVE-2022-45979HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .

  • CVE-2022-28917HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.10

    Tenda AX12 v22.03.01.21_cn was discovered to contain a stack overflow via the lanIp parameter in /goform/AdvSetLanIp.

  • CVE-2022-25561HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42DE00. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

  • CVE-2022-25556HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42E328. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

  • CVE-2021-46408HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX12 v22.03.01.21 was discovered to contain a stack buffer overflow in the function sub_422CE4. This vulnerability allows attackers to cause a Denial of Service (DoS) via the strcpy parameter.

Page 1 of 2