VYPR

Vendor CVEs

Tenda

All CVEs

2,140 total · sorted by risk
  • CVE-2022-30474CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request.

  • CVE-2022-30472CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat

  • CVE-2022-29591CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.

  • CVE-2022-28082CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.

  • CVE-2022-28561CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.10

    There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

  • CVE-2022-28560CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

  • CVE-2022-27022CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload.

  • CVE-2022-27016CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.

  • CVE-2022-26278CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

  • CVE-2022-27083CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.

  • CVE-2022-27082CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.

  • CVE-2022-27081CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.

  • CVE-2022-27080CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.

  • CVE-2022-27079CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.

  • CVE-2022-27078CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.

  • CVE-2022-27077CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.

  • CVE-2022-27076CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd.

  • CVE-2022-26536CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools.

  • CVE-2022-26290CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.

  • CVE-2022-26289CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.

  • CVE-2021-38278CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.

  • CVE-2022-25461CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function.

  • CVE-2022-25460CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.

  • CVE-2022-25459CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.

  • CVE-2022-25458CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function.

  • CVE-2022-25457CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.

  • CVE-2022-25456CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function.

  • CVE-2022-25455CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.

  • CVE-2022-25454CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.

  • CVE-2022-25453CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.

  • CVE-2022-25452CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function.

  • CVE-2022-25451CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function.

  • CVE-2022-25449CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.

  • CVE-2022-25448CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function.

  • CVE-2022-25447CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.

  • CVE-2022-25446CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function.

  • CVE-2022-25445CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

  • CVE-2022-25441CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.05

    Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function.

  • CVE-2022-25440CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.

  • CVE-2022-25439CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.

  • CVE-2022-25438CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.05

    Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.

  • CVE-2022-25437CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.

  • CVE-2022-25435CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function.

  • CVE-2022-25434CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function.

  • CVE-2022-25433CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo function.

  • CVE-2022-25431CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function.

  • CVE-2022-25429CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function.

  • CVE-2022-25428CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function.

  • CVE-2022-25427CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.

  • CVE-2021-46394CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.03

    There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check,…

Page 12 of 43