VYPR

AC6

by Tenda

CVEs (130)

  • CVE-2022-45646HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeedUp parameter in the formSetClientState function.

  • CVE-2022-45645HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceMac parameter in the addWifiMacFilter function.

  • CVE-2022-45644HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the formSetClientState function.

  • CVE-2022-45643HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the addWifiMacFilter function.

  • CVE-2022-45641HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Buffer Overflow via formSetMacFilterCfg.

  • CVE-2022-45640HigDec 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).

  • CVE-2022-36552HigAug 30, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.

  • CVE-2020-28095HigDec 30, 2020
    risk 0.49cvss 7.5epss 0.01

    On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.

  • CVE-2020-28094HigDec 28, 2020
    risk 0.49cvss 7.5epss 0.01

    On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to download malware named elive or CNKI E-Learning.

  • CVE-2025-55503HigAug 20, 2025
    risk 0.47cvss 7.3epss 0.00

    Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.

  • CVE-2025-31355HigAug 20, 2025
    risk 0.47cvss 7.2epss 0.00

    A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2025-50528HigJun 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.

  • CVE-2020-28093HigDec 28, 2020
    risk 0.47cvss 7.2epss 0.01

    On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.

  • CVE-2025-57296MedSep 19, 2025
    risk 0.43cvss 6.5epss 0.03

    Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the list and vlanId parameters, the sub_ADBC0 helper function concatenates these…

  • CVE-2024-10697MedNov 2, 2024
    risk 0.43cvss 6.3epss 0.26

    A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument mac leads to command injection. The…

  • CVE-2025-55495MedAug 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.

  • CVE-2025-55499MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.

  • CVE-2025-50641MedJul 1, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId.

  • CVE-2025-44172MedJun 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

  • CVE-2025-25507MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.01

    There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.

Page 6 of 7