VYPR

Vendor CVEs

Tenda

All CVEs

2,166 total · sorted by risk
  • CVE-2026-3275HigFeb 27, 2026
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Executing a manipulation of the argument entrys can lead to buffer overflow. The attack may be performed from remote. The exploit…

  • CVE-2026-3274HigFeb 27, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. The attack is possible to be carried out…

  • CVE-2026-3273HigFeb 27, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component httpd. Such manipulation of the argument mit_ssid_index leads to buffer overflow. The attack can be executed…

  • CVE-2026-3272HigFeb 27, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. This manipulation of the argument page causes buffer overflow. Remote exploitation of the attack is possible. The exploit…

  • CVE-2026-3271HigFeb 27, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pListFilterof of the component httpd. The manipulation of the argument page results in buffer overflow. The attack may be launched remotely. The exploit has been…

  • CVE-2026-3169HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in Tenda F453 1.0.0.3. This impacts the function fromSafeEmailFilter of the file /goform/SafeEmailFilter of the component httpd. The manipulation of the argument page leads to buffer overflow. Remote exploitation of the attack is…

  • CVE-2026-3168HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.03

    A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component httpd. Executing a manipulation of the argument page can lead to buffer overflow. The attack may be launched remotely. The…

  • CVE-2026-3167HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component httpd. Performing a manipulation of the argument webSiteId results in buffer overflow. The attack may be…

  • CVE-2026-3166HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit is…

  • CVE-2026-3165HigFeb 25, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform/AdvSetWrlsafeset of the component httpd. This manipulation of the argument mit_ssid causes buffer overflow. The attack can be initiated remotely. The exploit…

  • CVE-2026-3044HigFeb 24, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. The manipulation of the argument boundary leads to stack-based buffer overflow. It is possible to initiate the…

  • CVE-2026-2911HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.03

    A vulnerability has been found in Tenda FH451 up to 1.0.0.9. This issue affects some unknown processing of the file /goform/GstDhcpSetSer. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…

  • CVE-2026-2910HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.03

    A flaw has been found in Tenda HG9 300001138. This vulnerability affects unknown code of the file /boaform/formPing6. Executing a manipulation of the argument pingAddr can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been…

  • CVE-2026-2909HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the component Diagnostic Ping Endpoint. Performing a manipulation of the argument pingAddr results in stack-based buffer overflow. The attack is possible to be…

  • CVE-2026-2908HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in Tenda HG9 300001138. Affected by this issue is some unknown functionality of the file /boaform/formLoopBack of the component Loopback Detection Configuration Endpoint. Such manipulation of the argument Ethtype leads to stack-based…

  • CVE-2026-2907HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Tenda HG9 300001138. Affected by this vulnerability is an unknown functionality of the file /boaform/formgponConf of the component GPON Configuration Endpoint. This manipulation of the argument fmgpon_loid/fmgpon_loid_password causes stack-based…

  • CVE-2026-2906HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda HG9 300001138. Affected is an unknown function of the file /boaform/formSamba of the component Samba Configuration Endpoint. The manipulation of the argument sambaCap results in stack-based buffer overflow. The attack may be launched…

  • CVE-2026-2905HigFeb 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda HG9 300001138. This impacts an unknown function of the file /boaform/formWlanSetup of the component Wireless Configuration Endpoint. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be initiated…

  • CVE-2026-2886HigFeb 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Tenda A21 1.0.0.0. This affects the function set_device_name of the file /goform/SetOnlineDevName. This manipulation of the argument devName causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-2877HigFeb 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda A18 15.13.07.13. This affects the function strcpy of the file /goform/WifiExtraSet of the component Httpd Service. The manipulation of the argument wpapsk_crypto5g leads to stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2026-2876HigFeb 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda A18 15.13.07.13. This affects the function parse_macfilter_rule of the file /goform/setBlackRule. This manipulation of the argument deviceList causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-2874HigFeb 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Tenda A21 1.0.0.0. Impacted is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. Executing a manipulation of the argument ssid can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The…

  • CVE-2026-2873HigFeb 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in Tenda A21 1.0.0.0. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2026-2872HigFeb 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. Such manipulation of the argument devName/mac leads to stack-based…

  • CVE-2026-2871HigFeb 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Tenda A21 1.0.0.0. This affects the function fromSetIpMacBind of the file /goform/SetIpMacBind. This manipulation of the argument list causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-2870HigFeb 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipulation of the argument list results in stack-based buffer overflow. The attack can be executed remotely. The exploit has…

  • CVE-2026-2203HigFeb 9, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This manipulation of the argument timeZone causes buffer overflow. Remote exploitation of…

  • CVE-2026-2202HigFeb 9, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be launched remotely. The exploit…

  • CVE-2026-2187HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The…

  • CVE-2026-2186HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda RX3 16.03.13.11. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument list leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been…

  • CVE-2026-2185HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Tenda RX3 16.03.13.11. This issue affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. This manipulation of the argument devName/mac causes stack-based buffer overflow. The attack is…

  • CVE-2026-2181HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda RX3 16.03.13.11. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. The attack…

  • CVE-2026-2180HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda RX3 16.03.13.11. Affected is an unknown function of the file /goform/fast_setting_wifi_set. Such manipulation of the argument ssid_5g leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly…

  • CVE-2026-2140HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipulation of the argument deviceList leads to buffer overflow. The attack may be launched remotely. The exploit is…

  • CVE-2026-2139HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda TX9 up to 22.03.02.10_multi. Affected by this vulnerability is the function sub_432580 of the file /goform/fast_setting_wifi_set. This manipulation of the argument ssid causes buffer overflow. The attack may be initiated remotely. The…

  • CVE-2026-2138HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda TX9 up to 22.03.02.10_multi. Affected is the function sub_42D03C of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. The attack can be launched remotely. The exploit has been made public and…

  • CVE-2026-2137HigFeb 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /goform/SetIpMacBind. The manipulation of the argument list leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the…

  • CVE-2026-25857HigFeb 7, 2026
    risk 0.57cvss 8.8epss 0.03

    Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the…

  • CVE-2026-1637HigJan 29, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly…

  • CVE-2026-24440HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected…

  • CVE-2026-24428HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a low-privileged authenticated user to change the administrator account password. By sending a crafted request directly to the…

  • CVE-2026-1420HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.04

    A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This manipulation of the argument wpapsk_crypto causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be…

  • CVE-2026-1329HigJan 22, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Tenda AX1803 1.0.0.1. The affected element is the function fromGetWifiGuestBasic of the file /goform/WifiGuestSet. Executing a manipulation of the argument guestWrlPwd/guestEn/guestSsid/hideSsid/guestSecurity can lead to stack-based buffer overflow. The…

  • CVE-2026-22082HigJan 9, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting…

  • CVE-2026-22081HigJan 9, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by…

  • CVE-2026-22080HigJan 9, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could…

  • CVE-2026-22079HigJan 9, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on…

  • CVE-2026-0640HigJan 6, 2026
    risk 0.57cvss 8.8epss 0.03

    A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the…

  • CVE-2025-15356HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.04

    A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file /goform/PowerSaveSet. The manipulation of the argument powerSavingEn/time/powerSaveDelay/ledCloseType leads to buffer overflow. The attack can be initiated…

  • CVE-2025-15253HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…

Page 18 of 44