VYPR

Ac15 Firmware

by Tenda

CVEs (105)

  • CVE-2020-10987CriKEVJul 13, 2020
    risk 0.82cvss 9.8epss 0.80

    The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

  • CVE-2018-5767CriFeb 15, 2018
    risk 0.70cvss 9.8epss 0.47

    An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.

  • CVE-2022-28557CriMay 4, 2022
    risk 0.65cvss 9.8epss 0.23

    There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution

  • CVE-2021-44352CriDec 3, 2021
    risk 0.65cvss 9.8epss 0.13

    A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.

  • CVE-2026-24103CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.

  • CVE-2026-24105CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.

  • CVE-2026-24101CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.

  • CVE-2025-63666CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie…

  • CVE-2025-29462CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.

  • CVE-2025-25632CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.

  • CVE-2023-36103CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.

  • CVE-2023-39673CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().

  • CVE-2023-30378CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30376CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30375CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30373CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30372CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30371CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30370CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30369CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.

Page 1 of 6