VYPR

Vendor CVEs

Tenda

All CVEs

2,140 total · sorted by risk
  • CVE-2022-40862CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting

  • CVE-2022-40860CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList

  • CVE-2022-40853CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set

  • CVE-2022-38831CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList

  • CVE-2022-38830CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status.

  • CVE-2022-38829CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg.

  • CVE-2022-38326CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.

  • CVE-2022-38325CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.

  • CVE-2022-36586CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.

  • CVE-2022-36585CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.

  • CVE-2022-38314CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.

  • CVE-2022-38313CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.

  • CVE-2022-38312CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.

  • CVE-2022-38311CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.

  • CVE-2022-38310CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

  • CVE-2022-38309CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

  • CVE-2022-36587CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.

  • CVE-2022-36584CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.

  • CVE-2022-37176CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.

  • CVE-2022-37816CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.

  • CVE-2022-37815CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.

  • CVE-2022-37814CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.

  • CVE-2022-37813CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.

  • CVE-2022-37812CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.

  • CVE-2022-37811CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.

  • CVE-2022-37810CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

  • CVE-2022-37809CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.

  • CVE-2022-37808CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.

  • CVE-2022-37807CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.

  • CVE-2022-37806CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.

  • CVE-2022-37805CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.

  • CVE-2022-37804CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.

  • CVE-2022-37803CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.

  • CVE-2022-37802CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.

  • CVE-2022-37801CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.

  • CVE-2022-37800CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.

  • CVE-2022-37799CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.

  • CVE-2022-37798CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.

  • CVE-2022-37175CriAug 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.

  • CVE-2022-35201CriAug 19, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.

  • CVE-2022-36273CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.

  • CVE-2022-34597CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

  • CVE-2022-34596CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

  • CVE-2022-34595CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.

  • CVE-2022-32386CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.10

    Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.

  • CVE-2022-32385CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).

  • CVE-2022-32383CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the AdvSetMacMtuWan function.

  • CVE-2022-32032CriJul 1, 2022
    risk 0.64cvss 9.8epss 0.10

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule.

  • CVE-2022-30477CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetClientState request.

  • CVE-2022-30476CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetFirewallCfg request.

Page 11 of 43