Ac1206 Firmware
by Tenda
CVEs (44)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-37808 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB. | ||
| CVE-2022-37807 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState. | ||
| CVE-2022-37806 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient. | ||
| CVE-2022-37805 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle. | ||
| CVE-2022-37804 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo. | ||
| CVE-2022-37803 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat. | ||
| CVE-2022-37802 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting. | ||
| CVE-2022-37801 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand. | ||
| CVE-2022-37800 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic. | ||
| CVE-2022-37799 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement. | ||
| CVE-2022-37798 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer. | ||
| CVE-2025-3328 | Hig | 0.58 | 8.8 | 0.07 | Apr 7, 2025 | A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid/timeZone leads to buffer overflow. It is possible to… | ||
| CVE-2025-7544 | Hig | 0.57 | 8.8 | 0.02 | Jul 13, 2025 | A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be… | ||
| CVE-2025-4299 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2025 | A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been… | ||
| CVE-2025-4298 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2025 | A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been… | ||
| CVE-2024-10434 | Hig | 0.57 | 8.8 | 0.01 | Oct 28, 2024 | A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ate_Tenda_mfg_check_usb/ate_Tenda_mfg_check_usb3 of the file /goform/ate. The manipulation of the argument arg leads to stack-based buffer overflow. It is… | ||
| CVE-2022-42081 | Hig | 0.49 | 7.5 | 0.01 | Oct 12, 2022 | Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via sched_end_time parameter. | ||
| CVE-2022-42080 | Hig | 0.49 | 7.5 | 0.01 | Oct 12, 2022 | Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a heap overflow via sched_start_time parameter. | ||
| CVE-2022-42079 | Hig | 0.49 | 7.5 | 0.01 | Oct 12, 2022 | Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet. | ||
| CVE-2024-9793 | Med | 0.43 | 6.3 | 0.23 | Oct 10, 2024 | A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has… |
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.
- risk 0.64cvss 9.8epss 0.01
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.
- risk 0.58cvss 8.8epss 0.07
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid/timeZone leads to buffer overflow. It is possible to…
- risk 0.57cvss 8.8epss 0.02
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be…
- risk 0.57cvss 8.8epss 0.01
A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been…
- risk 0.57cvss 8.8epss 0.01
A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been…
- risk 0.57cvss 8.8epss 0.01
A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ate_Tenda_mfg_check_usb/ate_Tenda_mfg_check_usb3 of the file /goform/ate. The manipulation of the argument arg leads to stack-based buffer overflow. It is…
- risk 0.49cvss 7.5epss 0.01
Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via sched_end_time parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a heap overflow via sched_start_time parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.
- risk 0.43cvss 6.3epss 0.23
A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has…
Page 2 of 3