VYPR

Vendor CVEs

Tenda

All CVEs

2,166 total · sorted by risk
  • CVE-2026-15543HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.01

    A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

  • CVE-2026-51606HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC…

  • CVE-2026-51605HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.

  • CVE-2026-51604HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.

  • CVE-2026-51603HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. After completing the OPTIONS, DESCRIBE, and a legitimate first SETUP…

  • CVE-2026-51602HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing parser fails to validate the…

  • CVE-2026-51601HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker who has completed a standard…

  • CVE-2026-51600HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a…

  • CVE-2026-38142MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.01

    An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to execute arbitrary commands via a crafted payload injected into the mac parameter.

  • CVE-2026-13519HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.01

    A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made…

  • CVE-2026-13518HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.01

    A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2026-13517HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.01

    A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The attack may be launched remotely. The…

  • CVE-2026-13516HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.01

    A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in stack-based buffer overflow. The attack may be initiated…

  • CVE-2026-13515HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.01

    A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads to stack-based buffer overflow. The attack can be launched remotely. The…

  • CVE-2026-38571MedJun 26, 2026
    risk 0.00cvss 4.6epss 0.00

    Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain stored WPA2 credentials in cleartext and…

  • CVE-1999-1264Jan 21, 1999
    risk 0.00cvss —epss 0.01

    WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.

Page 44 of 44