VYPR

Hg9 Firmware

by Tenda

CVEs (7)

  • CVE-2022-30023HigJun 16, 2022
    risk 0.61cvss 8.8epss 0.39

    Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

  • CVE-2026-2910HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.03

    A flaw has been found in Tenda HG9 300001138. This vulnerability affects unknown code of the file /boaform/formPing6. Executing a manipulation of the argument pingAddr can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been…

  • CVE-2026-2909HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the component Diagnostic Ping Endpoint. Performing a manipulation of the argument pingAddr results in stack-based buffer overflow. The attack is possible to be…

  • CVE-2026-2908HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in Tenda HG9 300001138. Affected by this issue is some unknown functionality of the file /boaform/formLoopBack of the component Loopback Detection Configuration Endpoint. Such manipulation of the argument Ethtype leads to stack-based…

  • CVE-2026-2907HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Tenda HG9 300001138. Affected by this vulnerability is an unknown functionality of the file /boaform/formgponConf of the component GPON Configuration Endpoint. This manipulation of the argument fmgpon_loid/fmgpon_loid_password causes stack-based…

  • CVE-2026-2906HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda HG9 300001138. Affected is an unknown function of the file /boaform/formSamba of the component Samba Configuration Endpoint. The manipulation of the argument sambaCap results in stack-based buffer overflow. The attack may be launched…

  • CVE-2026-2905HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda HG9 300001138. This impacts an unknown function of the file /boaform/formWlanSetup of the component Wireless Configuration Endpoint. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be initiated…