Ac21 Firmware
by Tenda
CVEs (29)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-9605 | Cri | 0.64 | 9.8 | 0.05 | Aug 29, 2025 | A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely.… | ||
| CVE-2026-4565 | Hig | 0.57 | 8.8 | 0.01 | Mar 23, 2026 | A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely. The exploit is now public and… | ||
| CVE-2026-1637 | Hig | 0.57 | 8.8 | 0.01 | Jan 29, 2026 | A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly… | ||
| CVE-2025-13446 | Hig | 0.57 | 8.8 | 0.04 | Nov 20, 2025 | A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone/time leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The… | ||
| CVE-2025-13445 | Hig | 0.57 | 8.8 | 0.04 | Nov 20, 2025 | A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executing a manipulation of the argument list can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be… | ||
| CVE-2025-12611 | Hig | 0.57 | 8.8 | 0.01 | Nov 3, 2025 | A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads to buffer overflow. Remote exploitation of the attack is possible. The exploit… | ||
| CVE-2025-11091 | Hig | 0.57 | 8.8 | 0.01 | Sep 28, 2025 | A security flaw has been discovered in Tenda AC21 up to 16.03.08.16. Affected by this vulnerability is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. The attack can be launched remotely. The exploit… | ||
| CVE-2025-10838 | Hig | 0.57 | 8.8 | 0.01 | Sep 23, 2025 | A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function sub_45BB10 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is… | ||
| CVE-2023-24333 | Hig | 0.57 | 8.8 | 0.00 | Feb 21, 2024 | A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/openSchedWifi. | ||
| CVE-2022-44163 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2022 | Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function formSetMacFilterCfg. | ||
| CVE-2022-44158 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2022 | Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name. | ||
| CVE-2022-40076 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetWifiGusetBasic. | ||
| CVE-2022-40075 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, form_fast_setting_wifi_set. | ||
| CVE-2022-40074 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, setSchedWifi. | ||
| CVE-2022-40073 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, saveParentControlInfo. | ||
| CVE-2022-40072 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: setSmartPowerManagement. | ||
| CVE-2022-40071 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, formSetDeviceName. | ||
| CVE-2022-40070 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via bin/httpd, function: formSetFirewallCfg. | ||
| CVE-2022-40069 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | ]Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetSysTime. | ||
| CVE-2022-40068 | Hig | 0.49 | 7.5 | 0.01 | Sep 19, 2022 | Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetQosBand. |
- risk 0.64cvss 9.8epss 0.05
A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely.…
- risk 0.57cvss 8.8epss 0.01
A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely. The exploit is now public and…
- risk 0.57cvss 8.8epss 0.01
A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly…
- risk 0.57cvss 8.8epss 0.04
A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone/time leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The…
- risk 0.57cvss 8.8epss 0.04
A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executing a manipulation of the argument list can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be…
- risk 0.57cvss 8.8epss 0.01
A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads to buffer overflow. Remote exploitation of the attack is possible. The exploit…
- risk 0.57cvss 8.8epss 0.01
A security flaw has been discovered in Tenda AC21 up to 16.03.08.16. Affected by this vulnerability is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. The attack can be launched remotely. The exploit…
- risk 0.57cvss 8.8epss 0.01
A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function sub_45BB10 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is…
- risk 0.57cvss 8.8epss 0.00
A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/openSchedWifi.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetWifiGusetBasic.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, form_fast_setting_wifi_set.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, setSchedWifi.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, saveParentControlInfo.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: setSmartPowerManagement.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, formSetDeviceName.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via bin/httpd, function: formSetFirewallCfg.
- risk 0.49cvss 7.5epss 0.01
]Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetSysTime.
- risk 0.49cvss 7.5epss 0.01
Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetQosBand.
Page 1 of 2