Vendor CVEs
Tenda
All CVEs
2,140 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30474 | Cri | 0.64 | 9.8 | 0.01 | May 26, 2022 | Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request. | ||
| CVE-2022-30472 | Cri | 0.64 | 9.8 | 0.01 | May 26, 2022 | Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat | ||
| CVE-2022-29591 | Cri | 0.64 | 9.8 | 0.01 | May 10, 2022 | Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow. | ||
| CVE-2022-28082 | Cri | 0.64 | 9.8 | 0.09 | May 4, 2022 | Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList. | ||
| CVE-2022-28561 | Cri | 0.64 | 9.8 | 0.10 | May 3, 2022 | There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload | ||
| CVE-2022-28560 | Cri | 0.64 | 9.8 | 0.02 | May 3, 2022 | There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload | ||
| CVE-2022-27022 | Cri | 0.64 | 9.8 | 0.02 | Apr 7, 2022 | There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload. | ||
| CVE-2022-27016 | Cri | 0.64 | 9.8 | 0.02 | Apr 7, 2022 | There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn. | ||
| CVE-2022-26278 | Cri | 0.64 | 9.8 | 0.02 | Mar 28, 2022 | Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function. | ||
| CVE-2022-27083 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic. | ||
| CVE-2022-27082 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo. | ||
| CVE-2022-27081 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo. | ||
| CVE-2022-27080 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode. | ||
| CVE-2022-27079 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem. | ||
| CVE-2022-27078 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail. | ||
| CVE-2022-27077 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic. | ||
| CVE-2022-27076 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd. | ||
| CVE-2022-26536 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools. | ||
| CVE-2022-26290 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac. | ||
| CVE-2022-26289 | Cri | 0.64 | 9.8 | 0.03 | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand. | ||
| CVE-2021-38278 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2022 | Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function. | ||
| CVE-2022-25461 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function. | ||
| CVE-2022-25460 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function. | ||
| CVE-2022-25459 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function. | ||
| CVE-2022-25458 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function. | ||
| CVE-2022-25457 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function. | ||
| CVE-2022-25456 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function. | ||
| CVE-2022-25455 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function. | ||
| CVE-2022-25454 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function. | ||
| CVE-2022-25453 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function. | ||
| CVE-2022-25452 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function. | ||
| CVE-2022-25451 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function. | ||
| CVE-2022-25449 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function. | ||
| CVE-2022-25448 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function. | ||
| CVE-2022-25447 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function. | ||
| CVE-2022-25446 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function. | ||
| CVE-2022-25445 | Cri | 0.64 | 9.8 | 0.09 | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function. | ||
| CVE-2022-25441 | Cri | 0.64 | 9.8 | 0.05 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function. | ||
| CVE-2022-25440 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function. | ||
| CVE-2022-25439 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function. | ||
| CVE-2022-25438 | Cri | 0.64 | 9.8 | 0.05 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function. | ||
| CVE-2022-25437 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function. | ||
| CVE-2022-25435 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function. | ||
| CVE-2022-25434 | Cri | 0.64 | 9.8 | 0.09 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function. | ||
| CVE-2022-25433 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo function. | ||
| CVE-2022-25431 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function. | ||
| CVE-2022-25429 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function. | ||
| CVE-2022-25428 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function. | ||
| CVE-2022-25427 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function. | ||
| CVE-2021-46394 | Cri | 0.64 | 9.8 | 0.03 | Mar 4, 2022 | There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check,… |
- risk 0.64cvss 9.8epss 0.01
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request.
- risk 0.64cvss 9.8epss 0.01
Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat
- risk 0.64cvss 9.8epss 0.01
Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.
- risk 0.64cvss 9.8epss 0.09
Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.10
There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
- risk 0.64cvss 9.8epss 0.02
There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload
- risk 0.64cvss 9.8epss 0.02
There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload.
- risk 0.64cvss 9.8epss 0.02
There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.
- risk 0.64cvss 9.8epss 0.03
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function.
- risk 0.64cvss 9.8epss 0.09
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.
- risk 0.64cvss 9.8epss 0.05
Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
- risk 0.64cvss 9.8epss 0.05
Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function.
- risk 0.64cvss 9.8epss 0.09
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function.
- risk 0.64cvss 9.8epss 0.02
Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
- risk 0.64cvss 9.8epss 0.03
There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check,…
Page 12 of 43