VYPR

Vendor CVEs

Tenda

All CVEs

2,166 total · sorted by risk
  • CVE-2024-30623MedMar 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromDhcpListClient function.

  • CVE-2024-30603MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

  • CVE-2024-30598MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

  • CVE-2024-30597MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

  • CVE-2024-30590MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

  • CVE-2024-30586MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

  • CVE-2024-30585MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

  • CVE-2024-30594MedMar 28, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.

  • CVE-2024-3009MedMar 28, 2024
    risk 0.42cvss 6.3epss 0.08

    A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The attack can be launched…

  • CVE-2024-2991MedMar 27, 2024
    risk 0.42cvss 6.3epss 0.08

    A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The attack can be initiated remotely. The…

  • CVE-2024-2897MedMar 26, 2024
    risk 0.42cvss 6.3epss 0.08

    A vulnerability classified as critical has been found in Tenda AC7 15.03.06.44. Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2024-28547MedMar 18, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.

  • CVE-2023-40802MedAug 25, 2023
    risk 0.42cvss 6.5epss 0.01

    The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn

  • CVE-2022-45668MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2022-45667MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

  • CVE-2022-45674MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2022-45673MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

  • CVE-2022-40845MedNov 15, 2022
    risk 0.42cvss 6.5epss 0.01

    The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information…

  • CVE-2022-42087MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2022-42086MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.

  • CVE-2022-42078MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

  • CVE-2022-42077MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2021-42659MedMay 24, 2022
    risk 0.42cvss 6.5epss 0.01

    There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long…

  • CVE-2022-27375MedApr 25, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.

  • CVE-2022-27374MedApr 25, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.

  • CVE-2020-10986MedJul 13, 2020
    risk 0.42cvss 6.5epss 0.01

    A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.

  • CVE-2017-16936MedNov 24, 2017
    risk 0.42cvss 6.5epss 0.01

    Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01,…

  • CVE-2026-8264MedMay 11, 2026
    risk 0.41cvss 6.3epss 0.03

    A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command…

  • CVE-2026-7469MedApr 30, 2026
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public…

  • CVE-2026-7102MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacMac of the component httpd. The manipulation of the argument mac results in command injection. The attack can be executed remotely. The exploit has been made…

  • CVE-2026-6989MedApr 25, 2026
    risk 0.41cvss 6.3epss 0.03

    A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2026-5547MedApr 5, 2026
    risk 0.41cvss 6.3epss 0.02

    A vulnerability has been found in Tenda AC10 16.03.10.10_multi_TDE01. Affected is the function formAddMacfilterRule of the file /bin/httpd. Such manipulation leads to os command injection. It is possible to launch the attack remotely. Multiple endpoints might be affected.

  • CVE-2026-5153MedMar 30, 2026
    risk 0.41cvss 6.3epss 0.03

    A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. Executing a manipulation of the argument mac can lead to command injection. The attack may be launched remotely. The exploit has been published and…

  • CVE-2026-4554MedMar 22, 2026
    risk 0.41cvss 6.3epss 0.04

    A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-2930MedFeb 22, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. Such manipulation of the argument boundary leads to stack-based buffer overflow. The attack can be…

  • CVE-2026-1638MedJan 30, 2026
    risk 0.41cvss 6.3epss 0.02

    A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. The manipulation of the argument dmzIp results in command injection. The attack can be executed remotely. The exploit…

  • CVE-2025-15254MedDec 30, 2025
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in Tenda W6-S 1.0.0.4(510). This affects the function TendaAte of the file /goform/ate of the component ATE Service. Performing a manipulation results in os command injection. The attack may be initiated remotely. The exploit has been made public and…

  • CVE-2025-11523MedOct 9, 2025
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of the argument lanIp results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be…

  • CVE-2025-11121MedSep 28, 2025
    risk 0.41cvss 6.3epss 0.04

    A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. The manipulation of the argument lanIp leads to command injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-7415MedJul 10, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of the component httpd. The manipulation of the argument dest leads to command injection. The attack…

  • CVE-2025-5836MedJun 7, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may…

  • CVE-2025-5606MedJun 4, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetIptv of the file /goform/SetIPTVCfg. The manipulation of the argument list leads to command injection. The attack can be initiated remotely. The…

  • CVE-2025-44867MedMay 1, 2025
    risk 0.41cvss 6.3epss 0.01

    Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44866MedMay 1, 2025
    risk 0.41cvss 6.3epss 0.01

    Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44865MedMay 1, 2025
    risk 0.41cvss 6.3epss 0.01

    Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-44864MedMay 1, 2025
    risk 0.41cvss 6.3epss 0.01

    Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2025-1819MedMar 2, 2025
    risk 0.41cvss 6.3epss 0.02

    A vulnerability, which was classified as critical, was found in Tenda AC7 1200M 15.03.06.44. Affected is the function TendaTelnet of the file /goform/telnet. The manipulation of the argument lan_ip leads to os command injection. It is possible to launch the attack remotely. The…

  • CVE-2024-32302MedApr 17, 2024
    risk 0.41cvss 6.3epss 0.00

    Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.

  • CVE-2024-32288MedApr 17, 2024
    risk 0.41cvss 6.3epss 0.00

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function.

  • CVE-2024-32282MedApr 17, 2024
    risk 0.41cvss 6.3epss 0.01

    Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

Page 40 of 44