VYPR

Vendor CVEs

Tenda

All CVEs

2,140 total · sorted by risk
  • CVE-2026-1610HigJan 29, 2026
    risk 0.53cvss 8.1epss 0.01

    A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation results in hard-coded credentials. The attack is possible to be carried out remotely. A high degree of…

  • CVE-2025-32010HigAug 20, 2025
    risk 0.53cvss 8.1epss 0.01

    A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP response can lead to arbitrary code execution. An attacker can send an HTTP response to trigger this vulnerability.

  • CVE-2025-24322HigAug 20, 2025
    risk 0.53cvss 8.1epss 0.01

    An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lead to arbitrary code execution. An attacker can browse to the device to trigger this vulnerability.

  • CVE-2025-50263HigJul 3, 2025
    risk 0.53cvss 8.1epss 0.00

    Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.

  • CVE-2025-50258HigJul 3, 2025
    risk 0.53cvss 8.1epss 0.00

    Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.

  • CVE-2025-46634HigMay 1, 2025
    risk 0.53cvss 8.2epss 0.00

    Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenticate to the web management portal by collecting credentials from observed/collected traffic. It implements encryption,…

  • CVE-2025-46633HigMay 1, 2025
    risk 0.53cvss 8.2epss 0.00

    Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the client and server by collecting the symmetric AES key from collected and/or observed traffic. The AES key in sent in…

  • CVE-2025-46627HigMay 1, 2025
    risk 0.53cvss 8.2epss 0.00

    Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

  • CVE-2024-46450HigJan 16, 2025
    risk 0.53cvss 8.1epss 0.00

    Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.

  • CVE-2024-34974HigMay 14, 2024
    risk 0.53cvss 8.2epss 0.01

    Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.

  • CVE-2024-30612HigMar 28, 2024
    risk 0.53cvss 8.1epss 0.01

    Tenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState function.

  • CVE-2023-24332HigFeb 21, 2024
    risk 0.53cvss 8.1epss 0.01

    A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.

  • CVE-2023-43885HigNov 7, 2023
    risk 0.53cvss 8.1epss 0.01

    Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.

  • CVE-2026-5684HigApr 6, 2026
    risk 0.52cvss 8.0epss 0.01

    A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack requires access…

  • CVE-2025-12235HigOct 27, 2025
    risk 0.52cvss 8.0epss 0.05

    A vulnerability was found in Tenda CH22 1.0.0.1. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in buffer overflow. The attack must originate from the local network. The exploit has been made…

  • CVE-2025-3854HigApr 22, 2025
    risk 0.52cvss 8.0epss 0.01

    A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function EnableIpv6/UpdateWanModeMulti/UpdateIpv6Params/EditWlanMacList/Edit_List_SSID of the file /goform/aspForm of the component HTTP POST Request Handler. The…

  • CVE-2025-25679HigFeb 20, 2025
    risk 0.52cvss 8.0epss 0.00

    Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.

  • CVE-2024-46435HigFeb 10, 2025
    risk 0.52cvss 8.0epss 0.01

    A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. This vulnerability occurs due to improper input validation when handling…

  • CVE-2024-46431HigFeb 10, 2025
    risk 0.52cvss 8.0epss 0.00

    Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted data to the delWewifiPic function.

  • CVE-2024-52789HigNov 19, 2024
    risk 0.52cvss 8.0epss 0.00

    Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

  • CVE-2024-52788HigNov 19, 2024
    risk 0.52cvss 8.0epss 0.00

    Tenda W9 v1.0.0.7(4456) was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

  • CVE-2024-48192HigOct 17, 2024
    risk 0.52cvss 8.0epss 0.00

    Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root

  • CVE-2024-44859HigSep 4, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.

  • CVE-2024-39963HigJul 19, 2024
    risk 0.52cvss 8.0epss 0.02

    AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.

  • CVE-2024-35578HigMay 20, 2024
    risk 0.52cvss 8.0epss 0.00

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

  • CVE-2024-32303HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.00

    Tenda AC15 v15.03.20_multi, v15.03.05.19, and v15.03.05.18 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.

  • CVE-2024-32293HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.06

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function.

  • CVE-2024-32285HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.

  • CVE-2024-32310HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the PPW parameter of the fromWizardHandle function.

  • CVE-2024-30645HigMar 29, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.

  • CVE-2024-30634HigMar 29, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the mitInterface parameter in the fromAddressNat function.

  • CVE-2024-30626HigMar 29, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.

  • CVE-2024-30625HigMar 29, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function.

  • CVE-2024-30601HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.

  • CVE-2024-30600HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

  • CVE-2024-30607HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

  • CVE-2024-30606HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.

  • CVE-2024-30592HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.

  • CVE-2024-30583HigMar 28, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.

  • CVE-2024-25756HigFeb 22, 2024
    risk 0.52cvss 8.0epss 0.01

    A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet function.

  • CVE-2023-24334HigFeb 21, 2024
    risk 0.52cvss 8.0epss 0.00

    A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

  • CVE-2017-9138HigMay 21, 2017
    risk 0.52cvss 8.0epss 0.01

    There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). After connecting locally to a router in a wired or wireless manner, one can bypass intended access restrictions by sending shell commands directly and reading their…

  • CVE-2025-15371HigDec 31, 2025
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File. Such manipulation with the input Fireitup leads to hard-coded credentials. An attack has to be…

  • CVE-2022-42053HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.

  • CVE-2022-41396HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.

  • CVE-2022-41395HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.

  • CVE-2022-40847HigNov 15, 2022
    risk 0.51cvss 7.8epss 0.01

    In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerability allows attackers to run arbitrary commands on the server via the hostname parameter.

  • CVE-2022-38510HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    Tenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList.

  • CVE-2022-37824HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic.

  • CVE-2022-37823HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSer.

Page 27 of 43