VYPR

Vendor CVEs

Tenda

All CVEs

2,140 total · sorted by risk
  • CVE-2026-6029CriApr 10, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument User results in os command injection. The attack may be…

  • CVE-2026-6026CriApr 10, 2026
    risk 0.64cvss 9.8epss 0.03

    A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument enable results in os command…

  • CVE-2025-52221CriApr 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.

  • CVE-2026-4567CriMar 23, 2026
    risk 0.64cvss 9.8epss 0.04

    A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-4254CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local_2c causes stack-based buffer overflow. The attack can…

  • CVE-2026-4252CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is…

  • CVE-2026-24103CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.

  • CVE-2026-24105CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.

  • CVE-2026-24112CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addWewifiWhiteUser` function and processed by `sscanf` without size validation, it could lead to a buffer…

  • CVE-2026-24110CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule` function and are processed by `ret = sscanf(pRule, " %d\t%[^\t]\t%[^\n\r\t]", &dhcpsIndex, dhcpsIP, dhcpsMac);`, the lack of size…

  • CVE-2026-24101CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.

  • CVE-2026-24115CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before concatenating them into `gstruleQos` may lead to buffer overflow.

  • CVE-2026-24114CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`.

  • CVE-2026-24113CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using `sprintf` without proper size validation, it could lead to a…

  • CVE-2026-24111CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addAuthUser` function and processed by `sscanf` without size validation, it could lead to buffer overflow.

  • CVE-2026-24109CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this value is used in `sprintf` without validating variable sizes, it could lead to a buffer overflow vulnerability.

  • CVE-2026-24108CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using `sprintf` without proper size validation, it could lead to a…

  • CVE-2026-24107CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities.

  • CVE-2026-24436CriJan 26, 2026
    risk 0.64cvss 9.8epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.

  • CVE-2026-24429CriJan 26, 2026
    risk 0.64cvss 9.8epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to…

  • CVE-2025-69764CriJan 22, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.

  • CVE-2025-69766CriJan 21, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.

  • CVE-2025-69763CriJan 21, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.

  • CVE-2025-69762CriJan 21, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote code execution.

  • CVE-2025-15255CriDec 30, 2025
    risk 0.64cvss 9.8epss 0.04

    A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHandler. Executing a manipulation of the argument Cookie can lead to stack-based buffer overflow. The attack may be launched…

  • CVE-2025-15047CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Handler. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack can be initiated…

  • CVE-2025-15046CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component HTTP Request Handler. Such manipulation of the argument netmsk leads to stack-based buffer overflow. It is possible to launch the…

  • CVE-2025-15045CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit of the component HTTP Request Handler. This manipulation of the argument page causes stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2025-15044CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be…

  • CVE-2025-15010CriDec 22, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2025-15007CriDec 22, 2025
    risk 0.64cvss 9.8epss 0.01

    A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of the component HTTP Request Handler. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be…

  • CVE-2025-15006CriDec 22, 2025
    risk 0.64cvss 9.8epss 0.01

    A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of the component HTTP Request Handler. This manipulation of the argument ipaddress causes stack-based buffer overflow. The attack can…

  • CVE-2025-14879CriDec 18, 2025
    risk 0.64cvss 9.8epss 0.06

    A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Request Handler. This manipulation of the argument ssid_index causes stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2025-14878CriDec 18, 2025
    risk 0.64cvss 9.8epss 0.01

    A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirelessRestart of the component HTTP Request Handler. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be performed from…

  • CVE-2025-67073CriDec 17, 2025
    risk 0.64cvss 9.8epss 0.01

    A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to…

  • CVE-2025-14665CriDec 14, 2025
    risk 0.64cvss 9.8epss 0.01

    A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed…

  • CVE-2025-63666CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie…

  • CVE-2025-11423CriOct 8, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing a manipulation of the argument page results in memory corruption. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2025-11418CriOct 8, 2025
    risk 0.64cvss 9.8epss 0.06

    A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component HTTP Request Handler. The manipulation of the argument mit_ssid_index leads to stack-based buffer…

  • CVE-2025-10432CriSep 15, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function check_param_changed of the file /goform/AdvSetMacMtuWa of the component HTTP Request Handler. Performing manipulation of the argument wanMTU results in stack-based buffer overflow.…

  • CVE-2025-57085CriSep 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-9605CriAug 29, 2025
    risk 0.64cvss 9.8epss 0.05

    A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely.…

  • CVE-2025-9523CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in stack-based buffer overflow. It is possible to launch the attack remotely. The…

  • CVE-2025-55613CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.

  • CVE-2025-27129CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.

  • CVE-2025-45343CriMay 28, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules route.

  • CVE-2025-45779CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.07

    Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.

  • CVE-2025-45513CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.

  • CVE-2025-44899CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.00

    There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, the manipulation of the parameter shareSpeed leads to stack overflow.

  • CVE-2025-45042CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.

Page 2 of 43