VYPR

Vendor CVEs

Tenda

All CVEs

2,166 total · sorted by risk
  • CVE-2025-55499MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.

  • CVE-2025-7414MedJul 10, 2025
    risk 0.42cvss 6.3epss 0.13

    A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument domain leads to os command injection. The attack can be…

  • CVE-2025-50641MedJul 1, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId.

  • CVE-2025-44172MedJun 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

  • CVE-2025-4998MedMay 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacL…

  • CVE-2025-4997MedMay 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function UpdateWanParams/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList/Edit_BasicSSID/Edit_GuestSSIDFor2P4G/Edit_BasicSSID_5G/SetAPInfoById of the file…

  • CVE-2025-4867MedMay 18, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as problematic. Affected by this vulnerability is the function formArpNerworkSet of the file /goform/ArpNerworkSet. The manipulation leads to denial of service. The attack can be launched remotely. The…

  • CVE-2025-45514MedMay 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.

  • CVE-2025-44900MedMay 6, 2025
    risk 0.42cvss 6.5epss 0.00

    In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the parameter mac leads to stack overflow.

  • CVE-2025-46632MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.00

    Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.

  • CVE-2025-46630MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.

  • CVE-2025-46629MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.01

    Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet

  • CVE-2025-3167MedApr 3, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some unknown processing of the file /goform/VerAPIMant of the component API Interface. The manipulation of the argument getuid leads to denial of service. The…

  • CVE-2025-29218MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2025-29217MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2025-29215MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList.

  • CVE-2025-29118MedMar 19, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.

  • CVE-2025-25634MedMar 5, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based buffer overflow.

  • CVE-2025-1899MedMar 4, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack can be launched…

  • CVE-2025-1898MedMar 4, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi. Affected is an unknown function of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to buffer overflow. It is possible to launch the…

  • CVE-2025-1897MedMar 4, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi. This issue affects some unknown processing of the file /goform/SetNetControlList. The manipulation of the argument list leads to buffer overflow. The attack may be initiated…

  • CVE-2025-1896MedMar 4, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi. This vulnerability affects unknown code of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to buffer overflow. The attack can be initiated remotely. The exploit has…

  • CVE-2025-1895MedMar 4, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to buffer overflow. It is possible to initiate the attack remotely. The…

  • CVE-2025-25510MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.

  • CVE-2025-25507MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.01

    There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.

  • CVE-2025-25505MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.

  • CVE-2024-46437MedFeb 10, 2025
    risk 0.42cvss 6.5epss 0.01

    A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, including WiFi SSID, WiFi password, and base64-encoded administrator credentials,…

  • CVE-2024-46430MedFeb 10, 2025
    risk 0.42cvss 6.5epss 0.01

    Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the administrator password by sending a specially crafted HTTP POST request to the…

  • CVE-2025-0848MedJan 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The manipulation of the argument wpapsk_crypto5g leads to…

  • CVE-2024-11650MedNov 25, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2024-51409MedNov 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed format to a router running the corresponding version of the firmware.

  • CVE-2024-10750MedNov 4, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as problematic. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV?fgHPOST/goform/SysToo. The manipulation of the argument Content-Length leads to null pointer…

  • CVE-2024-10280MedOct 23, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to…

  • CVE-2024-44387MedAug 23, 2024
    risk 0.42cvss 6.5epss 0.00

    Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.

  • CVE-2024-40503MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packet handling.

  • CVE-2024-40417MedJul 10, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow.

  • CVE-2024-6403MedJun 28, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is the function formWifiBasicSet of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack…

  • CVE-2024-6402MedJun 28, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the function fromSetWirelessRepeat of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-34946MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.

  • CVE-2024-33213MedApr 23, 2024
    risk 0.42cvss 6.5epss 0.00

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic.

  • CVE-2024-32316MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.

  • CVE-2024-32311MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.

  • CVE-2024-32287MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.

  • CVE-2024-32313MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the adslPwd parameter of the formWanParameterSetting function.

  • CVE-2024-3908MedApr 17, 2024
    risk 0.42cvss 6.3epss 0.09

    A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. It is possible to launch the attack remotely. The…

  • CVE-2024-30840MedApr 15, 2024
    risk 0.42cvss 6.5epss 0.00

    A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.

  • CVE-2024-30639MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.

  • CVE-2024-30636MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.00

    Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.

  • CVE-2024-30633MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security parameter from the formWifiBasicSet function.

  • CVE-2024-30632MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security_5g parameter from formWifiBasicSet function.

Page 39 of 44