VYPR

Vendor CVEs

Tenda

All CVEs

2,166 total · sorted by risk
  • CVE-2021-31755CriKEVMay 7, 2021
    risk 0.83cvss 9.8epss 0.87

    An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

  • CVE-2020-10987CriKEVJul 13, 2020
    risk 0.82cvss 9.8epss 0.80

    The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

  • CVE-2018-14558CriKEVOct 30, 2018
    risk 0.76cvss 9.8epss 0.09

    An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute…

  • CVE-2018-5767CriFeb 15, 2018
    risk 0.70cvss 9.8epss 0.47

    An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.

  • CVE-2020-35391CriJan 1, 2021
    risk 0.68cvss 9.6epss 0.35

    Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either…

  • CVE-2015-5995CriDec 31, 2015
    risk 0.68cvss 9.8epss 0.19

    Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.

  • CVE-2022-42233CriOct 20, 2022
    risk 0.67cvss 9.8epss 0.43

    Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.

  • CVE-2023-27076CriApr 10, 2023
    risk 0.66cvss 9.8epss 0.23

    Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.

  • CVE-2022-35555CriAug 12, 2022
    risk 0.66cvss 9.8epss 0.26

    A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution.

  • CVE-2022-32054CriJul 7, 2022
    risk 0.66cvss 9.8epss 0.35

    Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.

  • CVE-2022-31446CriJun 14, 2022
    risk 0.66cvss 9.8epss 0.35

    Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.

  • CVE-2021-27691CriApr 16, 2021
    risk 0.66cvss 9.8epss 0.25

    Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted…

  • CVE-2026-86152CriSep 6, 2026
    risk 0.65cvss 10.0epss 0.03

    A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

  • CVE-2026-82695CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to…

  • CVE-2026-82694CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly…

  • CVE-2026-82693CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The…

  • CVE-2026-82542CriAug 30, 2026
    risk 0.65cvss 10.0epss 0.01

    A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to…

  • CVE-2026-6195CriApr 13, 2026
    risk 0.65cvss 9.8epss 0.03

    A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument admpass leads to os command injection. The…

  • CVE-2026-5853CriApr 9, 2026
    risk 0.65cvss 9.8epss 0.03

    A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument addrPrefixLen leads to os command…

  • CVE-2024-46628CriSep 26, 2024
    risk 0.65cvss 9.8epss 0.12

    Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.

  • CVE-2024-46048CriSep 13, 2024
    risk 0.65cvss 9.8epss 0.11

    Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

  • CVE-2023-51092CriDec 26, 2023
    risk 0.65cvss 9.8epss 0.13

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.

  • CVE-2023-49043CriNov 27, 2023
    risk 0.65cvss 9.8epss 0.13

    Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat.

  • CVE-2023-46370CriOct 25, 2023
    risk 0.65cvss 9.8epss 0.18

    Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.

  • CVE-2023-44018CriSep 27, 2023
    risk 0.65cvss 9.8epss 0.15

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function.

  • CVE-2023-25234CriFeb 27, 2023
    risk 0.65cvss 9.8epss 0.17

    Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.

  • CVE-2022-40855CriSep 23, 2022
    risk 0.65cvss 9.8epss 0.14

    Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code Execution (RCE) via the portMappingServer,…

  • CVE-2022-35559CriAug 12, 2022
    risk 0.65cvss 9.8epss 0.11

    A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and ping2 parameters for a stack overflow attack. An attacker can use this vulnerability to execute arbitrary code execution.

  • CVE-2022-29592CriMay 5, 2022
    risk 0.65cvss 9.8epss 0.20

    Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).

  • CVE-2022-28557CriMay 4, 2022
    risk 0.65cvss 9.8epss 0.23

    There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution

  • CVE-2022-25450CriMar 18, 2022
    risk 0.65cvss 9.8epss 0.12

    Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.

  • CVE-2022-24995CriMar 10, 2022
    risk 0.65cvss 9.8epss 0.14

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

  • CVE-2021-46393CriMar 4, 2022
    risk 0.65cvss 9.8epss 0.16

    There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security…

  • CVE-2022-25414CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.10

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.

  • CVE-2022-24144CriFeb 4, 2022
    risk 0.65cvss 9.8epss 0.19

    Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. This vulnerability allows attackers to execute arbitrary commands via the gateway, dns1, and dns2 parameters.

  • CVE-2021-44352CriDec 3, 2021
    risk 0.65cvss 9.8epss 0.13

    A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.

  • CVE-2026-86167CriSep 6, 2026
    risk 0.64cvss 9.9epss 0.03

    A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible.…

  • CVE-2026-86165CriSep 6, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-85109CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely.…

  • CVE-2026-38577CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.

  • CVE-2026-67967CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819

  • CVE-2026-67966CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.

  • CVE-2026-67965CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function

  • CVE-2026-19924CriAug 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-19747CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.03

    A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is…

  • CVE-2026-67822CriJul 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack…

  • CVE-2026-51846CriJun 19, 2026
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.

  • CVE-2026-51845CriJun 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.

  • CVE-2026-51844CriJun 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.

  • CVE-2026-51843CriJun 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.

Page 1 of 44