Ac15 Firmware
by Tenda
CVEs (105)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10987 | Cri | 0.82 | 9.8 | 0.80 | KEV | Jul 13, 2020 | The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter. | |
| CVE-2018-5767 | Cri | 0.70 | 9.8 | 0.47 | Feb 15, 2018 | An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header. | ||
| CVE-2022-28557 | Cri | 0.65 | 9.8 | 0.23 | May 4, 2022 | There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution | ||
| CVE-2021-44352 | Cri | 0.65 | 9.8 | 0.13 | Dec 3, 2021 | A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind. | ||
| CVE-2026-24103 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2026 | A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi. | ||
| CVE-2026-24105 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2026 | An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd. | ||
| CVE-2026-24101 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2026 | An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability. | ||
| CVE-2025-63666 | Cri | 0.64 | 9.8 | 0.00 | Nov 12, 2025 | Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie… | ||
| CVE-2025-29462 | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2025 | A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack. | ||
| CVE-2025-25632 | Cri | 0.64 | 9.8 | 0.02 | Mar 5, 2025 | Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet. | ||
| CVE-2023-36103 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request. | ||
| CVE-2023-39673 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2023 | Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34(). | ||
| CVE-2023-30378 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30376 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30375 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30373 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30372 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30371 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30370 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability. | ||
| CVE-2023-30369 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow. |
- risk 0.82cvss 9.8epss 0.80
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
- risk 0.70cvss 9.8epss 0.47
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.
- risk 0.65cvss 9.8epss 0.23
There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution
- risk 0.65cvss 9.8epss 0.13
A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.
- risk 0.64cvss 9.8epss 0.00
A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.
- risk 0.64cvss 9.8epss 0.00
Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie…
- risk 0.64cvss 9.8epss 0.01
A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.
- risk 0.64cvss 9.8epss 0.02
Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.
- risk 0.64cvss 9.8epss 0.01
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
- risk 0.64cvss 9.8epss 0.01
Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.
- risk 0.64cvss 9.8epss 0.01
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.
Page 1 of 6