VYPR

W15e Firmware

by Tenda

CVEs (31)

  • CVE-2026-30140HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive…

  • CVE-2023-27065HigMar 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2023-27064HigMar 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2023-27062HigMar 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2022-42060HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2017-14515HigSep 17, 2017
    risk 0.49cvss 7.5epss 0.01

    Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service (temporary HTTP outage and forced logout) via unspecified vectors.

  • CVE-2017-14514HigSep 17, 2017
    risk 0.49cvss 7.5epss 0.02

    Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a crafted URL.

  • CVE-2022-40845MedNov 15, 2022
    risk 0.42cvss 6.5epss 0.01

    The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information…

  • CVE-2022-40844MedNov 15, 2022
    risk 0.35cvss 5.4epss 0.01

    In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL body.

  • CVE-2022-40843MedNov 15, 2022
    risk 0.34cvss 4.9epss 0.29

    The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. This leads to authenticated attackers having the ability to read the routers syslog.log file which contains…

  • CVE-2022-40846MedNov 15, 2022
    risk 0.31cvss 4.8epss 0.01

    In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.

Page 2 of 2