VYPR

Vendor CVEs

Tenda

All CVEs

2,166 total · sorted by risk
  • CVE-2026-5549MedApr 5, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded…

  • CVE-2026-5527MedApr 5, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key …

  • CVE-2026-2148MedFeb 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely.…

  • CVE-2026-2147MedFeb 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Management Interface. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. The…

  • CVE-2025-14286MedDec 9, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be…

  • CVE-2025-60661MedOct 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.

  • CVE-2025-57219MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components via a crafted request.

  • CVE-2025-57218MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.01

    Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sub_46284C.

  • CVE-2025-57217MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.01

    Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter in the function R7WebsSecurityHandler.

  • CVE-2025-52054MedAug 28, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. This allows an unauthenticated attacker…

  • CVE-2025-51082MedJul 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack-based buffer overflow.

  • CVE-2025-3237MedApr 4, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/wrlwpsset. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-3236MedApr 4, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/VirSerDMZ of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be…

  • CVE-2025-2994MedMar 31, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to initiate the…

  • CVE-2025-2992MedMar 31, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vulnerability is an unknown functionality of the file /goform/AdvSetWrlsafeset of the component Web Management Interface. The manipulation leads to improper access controls. The…

  • CVE-2025-2991MedMar 31, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an unknown function of the file /goform/AdvSetWrlmacfilter of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to launch the…

  • CVE-2025-2990MedMar 31, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/AdvSetWrlGstset of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be…

  • CVE-2025-2989MedMar 31, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/AdvSetWrl of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be…

  • CVE-2024-35576MedMay 20, 2024
    risk 0.34cvss 5.2epss 0.00

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.

  • CVE-2023-4498MedSep 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to authenticated users only

  • CVE-2022-40843MedNov 15, 2022
    risk 0.34cvss 4.9epss 0.29

    The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. This leads to authenticated attackers having the ability to read the routers syslog.log file which contains…

  • CVE-2026-11493MedJun 8, 2026
    risk 0.33cvss 5.0epss 0.00

    A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements. The attack is only possible within the local network. A…

  • CVE-2026-36778MedJun 9, 2026
    risk 0.32cvss 4.9epss 0.00

    Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the username parameter of the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP…

  • CVE-2024-0930MedJan 26, 2024
    risk 0.32cvss 4.7epss 0.15

    A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function fromSetWirelessRepeat. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The…

  • CVE-2021-40546MedSep 5, 2023
    risk 0.32cvss 4.9epss 0.01

    Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi.

  • CVE-2026-8265MedMay 11, 2026
    risk 0.31cvss 4.7epss 0.04

    A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated…

  • CVE-2026-8263MedMay 11, 2026
    risk 0.31cvss 4.7epss 0.05

    A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to…

  • CVE-2026-8259MedMay 11, 2026
    risk 0.31cvss 4.7epss 0.04

    A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The…

  • CVE-2026-5339MedApr 2, 2026
    risk 0.31cvss 4.7epss 0.06

    A vulnerability was detected in Tenda G103 1.0.0.5. The impacted element is the function action_set_net_settings of the file gpon.lua of the component Setting Handler. Performing a manipulation of the argument authLoid/authLoidPassword/authPassword/authSerialNo/authType/oltType/u…

  • CVE-2026-5338MedApr 2, 2026
    risk 0.31cvss 4.7epss 0.05

    A security vulnerability has been detected in Tenda G103 1.0.0.5. The affected element is the function action_set_system_settings of the file system.lua of the component Setting Handler. Such manipulation of the argument lanIp leads to command injection. The attack may be…

  • CVE-2026-4253MedMar 16, 2026
    risk 0.31cvss 4.7epss 0.07

    A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of the component Web Interface. The manipulation of the argument wans.policy.list1 results in os command injection. It is possible to…

  • CVE-2026-1690MedJan 30, 2026
    risk 0.31cvss 4.7epss 0.04

    A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /boaform/formSysCmd. This manipulation of the argument sysCmd causes command injection. The attack may be initiated remotely. The exploit has been published and…

  • CVE-2025-5763MedJun 6, 2025
    risk 0.31cvss 4.7epss 0.05

    A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the file apollo. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been…

  • CVE-2025-4357MedMay 6, 2025
    risk 0.31cvss 4.7epss 0.15

    A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /goform/telnet. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2024-32315MedApr 17, 2024
    risk 0.31cvss 4.7epss 0.00

    Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.

  • CVE-2024-0932MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This issue affects the function setSmartPowerManagement. The manipulation of the argument time leads to stack-based buffer overflow. The attack may be initiated remotely.…

  • CVE-2024-0931MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. This vulnerability affects the function saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to stack-based buffer overflow. The attack can be initiated remotely.…

  • CVE-2024-0929MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Affected by this issue is the function fromNatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The…

  • CVE-2024-0928MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been declared as critical. Affected by this vulnerability is the function fromDhcpListClient. The manipulation of the argument page/listN leads to stack-based buffer overflow. The attack can be launched…

  • CVE-2024-0927MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been classified as critical. Affected is the function fromAddressNat. The manipulation of the argument entrys/mitInterface/page leads to stack-based buffer overflow. It is possible to launch the attack…

  • CVE-2024-0926MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This issue affects the function formWifiWpsOOB. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been…

  • CVE-2024-0925MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This vulnerability affects the function formSetVirtualSer. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be initiated remotely. The…

  • CVE-2024-0924MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function formSetPPTPServer. The manipulation of the argument startIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The…

  • CVE-2024-0923MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely.…

  • CVE-2024-0922MedJan 26, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this vulnerability is the function formQuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be launched remotely. The…

  • CVE-2022-40846MedNov 15, 2022
    risk 0.31cvss 4.8epss 0.01

    In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.

  • CVE-2025-25458MedApr 15, 2025
    risk 0.30cvss 4.6epss 0.00

    Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

  • CVE-2025-25453MedApr 15, 2025
    risk 0.30cvss 4.6epss 0.00

    Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.

  • CVE-2024-25373MedFeb 15, 2024
    risk 0.30cvss 4.6epss 0.00

    Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.

  • CVE-2026-27513MedFeb 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a cross-site request forgery (CSRF) vulnerability in the web-based administrative interface. The interface does not implement anti-CSRF protections, allowing an attacker to induce an authenticated…