VYPR

Ac18 Firmware

by Tenda

CVEs (121)

  • CVE-2022-31446CriJun 14, 2022
    risk 0.66cvss 9.8epss 0.34

    Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.

  • CVE-2026-31255CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.

  • CVE-2024-57583CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.

  • CVE-2024-57582CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.

  • CVE-2024-57581CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

  • CVE-2024-57580CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

  • CVE-2024-57579CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientState function.

  • CVE-2024-57575CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

  • CVE-2024-33182CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.

  • CVE-2024-33180CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.

  • CVE-2024-33835CriMay 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.

  • CVE-2024-28545CriMar 26, 2024
    risk 0.64cvss 9.8epss 0.02

    Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.

  • CVE-2024-28537CriMar 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.

  • CVE-2024-28553CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.

  • CVE-2024-28535CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.

  • CVE-2023-38823CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.

  • CVE-2023-30135CriMay 5, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.

  • CVE-2023-24170CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.

  • CVE-2023-24169CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.

  • CVE-2023-24167CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node.

Page 1 of 7