VYPR

Vendor CVEs

Tenda

All CVEs

2,140 total · sorted by risk
  • CVE-2025-44877CriMay 2, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44872CriMay 2, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-45429CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.01

    In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.

  • CVE-2025-45428CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.01

    In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

  • CVE-2025-45427CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

  • CVE-2025-25456CriApr 15, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.

  • CVE-2025-29462CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.

  • CVE-2025-29135CriMar 24, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.

  • CVE-2025-29100CriMar 24, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.

  • CVE-2025-29137CriMar 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.

  • CVE-2025-29386CriMar 14, 2025
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

  • CVE-2025-29385CriMar 14, 2025
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

  • CVE-2025-29384CriMar 14, 2025
    risk 0.64cvss 9.8epss 0.02

    In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

  • CVE-2025-29031CriMar 14, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.

  • CVE-2025-29030CriMar 14, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.

  • CVE-2025-29029CriMar 14, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.

  • CVE-2025-25632CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.

  • CVE-2025-25678CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

  • CVE-2025-25676CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.

  • CVE-2025-25675CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function,…

  • CVE-2025-25674CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.

  • CVE-2025-25668CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.

  • CVE-2025-25667CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.

  • CVE-2025-25664CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.

  • CVE-2025-25663CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.

  • CVE-2025-25662CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via the argument remark/type/time.

  • CVE-2025-25343CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.

  • CVE-2024-57703CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow.

  • CVE-2024-57583CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.

  • CVE-2024-57582CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.

  • CVE-2024-57581CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

  • CVE-2024-57580CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

  • CVE-2024-57579CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientState function.

  • CVE-2024-57575CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

  • CVE-2024-57483CriJan 14, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.

  • CVE-2025-22949CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.

  • CVE-2025-22946CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.

  • CVE-2024-52275CriDec 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromWizardHandle modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50.

  • CVE-2024-52274CriDec 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoubleL2tpConfig->guest_ip_check(overflow arg: mask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50

  • CVE-2024-52273CriDec 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoublePppoeConfig->guest_ip_check(overflow arg: mask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50

  • CVE-2024-52272CriDec 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromAdvSetLanip(overflow arg:lanMask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50

  • CVE-2024-52714CriNov 19, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.

  • CVE-2024-46652CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.

  • CVE-2024-46049CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.

  • CVE-2024-46046CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.

  • CVE-2024-46045CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.

  • CVE-2024-46044CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.

  • CVE-2023-36103CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.

  • CVE-2024-44557CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.

  • CVE-2024-44555CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.

Page 3 of 43