VYPR

Tx9 Firmware

by Tenda

CVEs (4)

  • CVE-2026-2140HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipulation of the argument deviceList leads to buffer overflow. The attack may be launched remotely. The exploit is…

  • CVE-2026-2139HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda TX9 up to 22.03.02.10_multi. Affected by this vulnerability is the function sub_432580 of the file /goform/fast_setting_wifi_set. This manipulation of the argument ssid causes buffer overflow. The attack may be initiated remotely. The…

  • CVE-2026-2138HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda TX9 up to 22.03.02.10_multi. Affected is the function sub_42D03C of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. The attack can be launched remotely. The exploit has been made public and…

  • CVE-2023-47422HigFeb 20, 2024
    risk 0.57cvss 8.8epss 0.00

    An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.