VYPR

Vendor CVEs

Tenda

All CVEs

2,140 total · sorted by risk
  • CVE-2025-25505MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.

  • CVE-2024-46437MedFeb 10, 2025
    risk 0.42cvss 6.5epss 0.01

    A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, including WiFi SSID, WiFi password, and base64-encoded administrator credentials,…

  • CVE-2024-46430MedFeb 10, 2025
    risk 0.42cvss 6.5epss 0.01

    Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the administrator password by sending a specially crafted HTTP POST request to the…

  • CVE-2025-0848MedJan 30, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The manipulation of the argument wpapsk_crypto5g leads to…

  • CVE-2024-11650MedNov 25, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2024-51409MedNov 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed format to a router running the corresponding version of the firmware.

  • CVE-2024-10750MedNov 4, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as problematic. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV?fgHPOST/goform/SysToo. The manipulation of the argument Content-Length leads to null pointer…

  • CVE-2024-10280MedOct 23, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to…

  • CVE-2024-44387MedAug 23, 2024
    risk 0.42cvss 6.5epss 0.00

    Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.

  • CVE-2024-40503MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packet handling.

  • CVE-2024-40417MedJul 10, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow.

  • CVE-2024-6403MedJun 28, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is the function formWifiBasicSet of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack…

  • CVE-2024-6402MedJun 28, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the function fromSetWirelessRepeat of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-34946MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.

  • CVE-2024-33213MedApr 23, 2024
    risk 0.42cvss 6.5epss 0.00

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic.

  • CVE-2024-32316MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.

  • CVE-2024-32311MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.

  • CVE-2024-32287MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.

  • CVE-2024-32313MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the adslPwd parameter of the formWanParameterSetting function.

  • CVE-2024-3908MedApr 17, 2024
    risk 0.42cvss 6.3epss 0.09

    A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. It is possible to launch the attack remotely. The…

  • CVE-2024-30840MedApr 15, 2024
    risk 0.42cvss 6.5epss 0.00

    A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.

  • CVE-2024-30639MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.

  • CVE-2024-30636MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.00

    Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.

  • CVE-2024-30633MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security parameter from the formWifiBasicSet function.

  • CVE-2024-30632MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security_5g parameter from formWifiBasicSet function.

  • CVE-2024-30623MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromDhcpListClient function.

  • CVE-2024-30603MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

  • CVE-2024-30598MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

  • CVE-2024-30597MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

  • CVE-2024-30590MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

  • CVE-2024-30586MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

  • CVE-2024-30585MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

  • CVE-2024-30594MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.

  • CVE-2024-3009MedMar 28, 2024
    risk 0.42cvss 6.3epss 0.08

    A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The attack can be launched…

  • CVE-2024-2991MedMar 27, 2024
    risk 0.42cvss 6.3epss 0.08

    A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The attack can be initiated remotely. The…

  • CVE-2024-2897MedMar 26, 2024
    risk 0.42cvss 6.3epss 0.08

    A vulnerability classified as critical has been found in Tenda AC7 15.03.06.44. Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2024-28547MedMar 18, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.

  • CVE-2023-40802MedAug 25, 2023
    risk 0.42cvss 6.5epss 0.01

    The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn

  • CVE-2022-45668MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2022-45667MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

  • CVE-2022-45674MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2022-45673MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

  • CVE-2022-40845MedNov 15, 2022
    risk 0.42cvss 6.5epss 0.01

    The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information…

  • CVE-2022-42087MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2022-42086MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.

  • CVE-2022-42078MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

  • CVE-2022-42077MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2021-42659MedMay 24, 2022
    risk 0.42cvss 6.5epss 0.01

    There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long…

  • CVE-2022-27375MedApr 25, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.

  • CVE-2022-27374MedApr 25, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.

Page 39 of 43