VYPR

Vendor CVEs

Tenda

All CVEs

2,140 total · sorted by risk
  • CVE-2025-15180HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was identified in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/webExcptypemanFilte of the component HTTP Request Handler. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be…

  • CVE-2025-15179HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was determined in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/qossetting. This manipulation of the argument page causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and…

  • CVE-2025-15178HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/VirtualSer of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely.…

  • CVE-2025-15177HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been found in Tenda WH450 1.0.0.18. This vulnerability affects unknown code of the file /goform/SetIpBind of the component HTTP Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely.…

  • CVE-2025-15164HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A security flaw has been discovered in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the argument page results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been released to…

  • CVE-2025-15163HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was identified in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The…

  • CVE-2025-15162HigDec 29, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was determined in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/RouteStatic. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be executed remotely. The…

  • CVE-2025-15161HigDec 28, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was found in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/PPTPUserSetting. Performing a manipulation of the argument delno results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2025-15160HigDec 28, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been found in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/PPTPServer. Such manipulation of the argument ip1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public…

  • CVE-2025-15008HigDec 22, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack may be initiated remotely. The…

  • CVE-2025-55503HigAug 20, 2025
    risk 0.47cvss 7.3epss 0.00

    Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.

  • CVE-2025-31355HigAug 20, 2025
    risk 0.47cvss 7.2epss 0.00

    A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2025-50528HigJun 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.

  • CVE-2025-46626HigMay 1, 2025
    risk 0.47cvss 7.3epss 0.00

    Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.

  • CVE-2025-0528HigJan 17, 2025
    risk 0.47cvss 7.2epss 0.06

    A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The…

  • CVE-2024-44386HigAug 23, 2024
    risk 0.47cvss 7.3epss 0.00

    Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.

  • CVE-2024-34338HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.03

    Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest parameter in /goform/getTraceroute. This vulnerability allows attackers to execute arbitrary commands with root privileges. Authentication is required to…

  • CVE-2024-33211HigApr 23, 2024
    risk 0.47cvss 7.3epss 0.00

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter in ip/goform/QuickIndex.

  • CVE-2024-0996HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability classified as critical has been found in Tenda i9 1.0.0.9(4122). This affects the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate…

  • CVE-2024-0995HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been rated as critical. Affected by this issue is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The…

  • CVE-2024-0994HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been declared as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow.…

  • CVE-2024-0993HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda i6 1.0.0.9(3857). It has been classified as critical. Affected is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. It is…

  • CVE-2024-0992HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda i6 1.0.0.9(3857) and classified as critical. This issue affects the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be…

  • CVE-2024-0991HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability has been found in Tenda i6 1.0.0.9(3857) and classified as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack…

  • CVE-2024-0990HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability, which was classified as critical, was found in Tenda i6 1.0.0.9(3857). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component httpd. The manipulation of the argument ping1 leads to stack-based buffer overflow. It is possible…

  • CVE-2024-0534HigJan 15, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability classified as critical has been found in Tenda A15 15.13.07.13. Affected is an unknown function of the file /goform/SetOnlineDevName of the component Web-based Management Interface. The manipulation of the argument mac leads to stack-based buffer overflow. It is…

  • CVE-2024-0533HigJan 15, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda A15 15.13.07.13. It has been rated as critical. This issue affects some unknown processing of the file /goform/SetOnlineDevName of the component Web-based Management Interface. The manipulation of the argument devName leads to stack-based…

  • CVE-2024-0532HigJan 15, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as critical. This vulnerability affects the function set_repeat5 of the file /goform/WifiExtraSet of the component Web-based Management Interface. The manipulation of the argument…

  • CVE-2024-0531HigJan 15, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda A15 15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/setBlackRule of the component Web-based Management Interface. The manipulation of the argument deviceList leads to stack-based buffer…

  • CVE-2023-0782HigFeb 11, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit…

  • CVE-2022-45997HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.

  • CVE-2022-45996HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.

  • CVE-2022-40861HigSep 23, 2022
    risk 0.47cvss 7.2epss 0.01

    Tenda AC18 router V15.03.05.19 contains a stack overflow vulnerability in the formSetQosBand->FUN_0007db78 function with the request /goform/SetNetControlList/

  • CVE-2022-36571HigAug 31, 2022
    risk 0.47cvss 7.2epss 0.01

    Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.

  • CVE-2022-36570HigAug 31, 2022
    risk 0.47cvss 7.2epss 0.01

    Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.

  • CVE-2020-20746HigSep 30, 2021
    risk 0.47cvss 7.2epss 0.03

    A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.

  • CVE-2020-28093HigDec 28, 2020
    risk 0.47cvss 7.2epss 0.01

    On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.

  • CVE-2025-46635HigMay 1, 2025
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces on the router allows an attacker (who is authenticated to the guest Wi-Fi) to access resources on the router and/or resources and…

  • CVE-2025-29387HigMar 14, 2025
    risk 0.46cvss 7.1epss 0.01

    In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

  • CVE-2023-43886HigNov 7, 2023
    risk 0.46cvss 7.1epss 0.01

    A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to overwrite memory.

  • CVE-2025-9090MedAug 17, 2025
    risk 0.45cvss 6.3epss 0.14

    A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2025-11666MedOct 13, 2025
    risk 0.44cvss 6.7epss 0.00

    A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can…

  • CVE-2025-52363MedJul 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtaining administrative access

  • CVE-2024-40412MedJul 10, 2024
    risk 0.44cvss 6.8epss 0.00

    Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.

  • CVE-2024-32290MedApr 17, 2024
    risk 0.44cvss 6.7epss 0.01

    Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.

  • CVE-2023-34571MedJun 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet.

  • CVE-2023-34570MedJun 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.

  • CVE-2023-34569MedJun 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

  • CVE-2023-34568MedJun 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

  • CVE-2023-34567MedJun 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.

Page 37 of 43