VYPR

AC18

by Tenda

CVEs (110)

  • CVE-2025-5606MedJun 4, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetIptv of the file /goform/SetIPTVCfg. The manipulation of the argument list leads to command injection. The attack can be initiated remotely. The…

  • CVE-2024-2854MedMar 24, 2024
    risk 0.41cvss 6.3epss 0.04

    A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetSambaConf of the file /goform/setsambacfg. The manipulation of the argument usbName leads to os command injection. It is possible to launch the attack remotely. The…

  • CVE-2024-57577MedJan 16, 2025
    risk 0.37cvss 5.7epss 0.00

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

  • CVE-2025-8182MedJul 26, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component Samba. The manipulation leads to weak password requirements. The attack can be initiated remotely. The…

  • CVE-2025-63834MedNov 10, 2025
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.

  • CVE-2025-60661MedOct 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.

  • CVE-2024-28550MedMar 18, 2024
    risk 0.28cvss 4.3epss 0.00

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.

  • CVE-2024-2560MedMar 17, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function fromSysToolRestoreSet of the file /goform/SysToolRestoreSet. The manipulation leads to cross-site request forgery. The attack can be launched remotely.…

  • CVE-2024-2559MedMar 17, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in Tenda AC18 15.03.05.05. Affected is the function fromSysToolReboot of the file /goform/SysToolReboot. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has…

  • CVE-2026-38142MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.01

    An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to execute arbitrary commands via a crafted payload injected into the mac parameter.

Page 6 of 6