Vendor CVEs
Tenda
All CVEs
2,140 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-28537 | Cri | 0.64 | 9.8 | 0.01 | Mar 18, 2024 | Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function. | ||
| CVE-2024-28383 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2024 | Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function. | ||
| CVE-2024-28553 | Cri | 0.64 | 9.8 | 0.01 | Mar 12, 2024 | Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function. | ||
| CVE-2024-28535 | Cri | 0.64 | 9.8 | 0.01 | Mar 12, 2024 | Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function. | ||
| CVE-2024-25751 | Cri | 0.64 | 9.8 | 0.01 | Feb 26, 2024 | A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime function. | ||
| CVE-2024-24543 | Cri | 0.64 | 9.8 | 0.01 | Feb 5, 2024 | Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data. | ||
| CVE-2023-51970 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv. | ||
| CVE-2023-51969 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo. | ||
| CVE-2023-51968 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo. | ||
| CVE-2023-51967 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo. | ||
| CVE-2023-51962 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo. | ||
| CVE-2023-51965 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo. | ||
| CVE-2023-51964 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo. | ||
| CVE-2023-51963 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo. | ||
| CVE-2023-51960 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv. | ||
| CVE-2023-51959 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv. | ||
| CVE-2023-51958 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv. | ||
| CVE-2023-51957 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv. | ||
| CVE-2023-51956 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv | ||
| CVE-2023-51955 | Cri | 0.64 | 9.8 | 0.00 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv. | ||
| CVE-2023-51954 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv. | ||
| CVE-2023-51953 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv. | ||
| CVE-2023-51952 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv. | ||
| CVE-2023-51966 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo. | ||
| CVE-2023-51961 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv. | ||
| CVE-2023-51972 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp. | ||
| CVE-2023-51971 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo. | ||
| CVE-2023-50585 | Cri | 0.64 | 9.8 | 0.01 | Jan 9, 2024 | Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function. | ||
| CVE-2023-51812 | Cri | 0.64 | 9.8 | 0.01 | Jan 4, 2024 | Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList. | ||
| CVE-2023-51102 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet. | ||
| CVE-2023-51101 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo. | ||
| CVE-2023-51100 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo . | ||
| CVE-2023-51099 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand . | ||
| CVE-2023-51098 | Cri | 0.64 | 9.8 | 0.02 | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo . | ||
| CVE-2023-51097 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2023 | Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetAutoPing. | ||
| CVE-2023-51094 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet. | ||
| CVE-2023-51093 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo. | ||
| CVE-2023-51091 | Cri | 0.64 | 9.8 | 0.08 | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler. | ||
| CVE-2023-51090 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig. | ||
| CVE-2023-51095 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy. | ||
| CVE-2023-50992 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function. | ||
| CVE-2023-50990 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function. | ||
| CVE-2023-50989 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function. | ||
| CVE-2023-50988 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function. | ||
| CVE-2023-50987 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function. | ||
| CVE-2023-50986 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function. | ||
| CVE-2023-50985 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function. | ||
| CVE-2023-50984 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function. | ||
| CVE-2023-50983 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2023 | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function. | ||
| CVE-2023-49411 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode. |
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
- risk 0.64cvss 9.8epss 0.01
Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.
- risk 0.64cvss 9.8epss 0.01
A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime function.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv
- risk 0.64cvss 9.8epss 0.00
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.
- risk 0.64cvss 9.8epss 0.02
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
- risk 0.64cvss 9.8epss 0.01
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.
- risk 0.64cvss 9.8epss 0.01
Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
- risk 0.64cvss 9.8epss 0.01
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.01
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet.
- risk 0.64cvss 9.8epss 0.01
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo.
- risk 0.64cvss 9.8epss 0.02
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .
- risk 0.64cvss 9.8epss 0.02
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .
- risk 0.64cvss 9.8epss 0.02
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo .
- risk 0.64cvss 9.8epss 0.01
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetAutoPing.
- risk 0.64cvss 9.8epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.
- risk 0.64cvss 9.8epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.
- risk 0.64cvss 9.8epss 0.08
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.
- risk 0.64cvss 9.8epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.
- risk 0.64cvss 9.8epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.
- risk 0.64cvss 9.8epss 0.02
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.
- risk 0.64cvss 9.8epss 0.01
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.
- risk 0.64cvss 9.8epss 0.02
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.
Page 5 of 43