Vendor CVEs
Tenda
All CVEs
2,140 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49409 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet. | ||
| CVE-2023-49408 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name. | ||
| CVE-2023-49406 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet. | ||
| CVE-2023-49405 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg. | ||
| CVE-2023-49404 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet. | ||
| CVE-2023-50002 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode. | ||
| CVE-2023-50001 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline. | ||
| CVE-2023-50000 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode. | ||
| CVE-2023-49999 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition. | ||
| CVE-2023-49410 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status. | ||
| CVE-2023-49403 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools. | ||
| CVE-2023-49402 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg. | ||
| CVE-2023-49436 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. | ||
| CVE-2023-49435 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 is vulnerable to command injection. | ||
| CVE-2023-49434 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList. | ||
| CVE-2023-49433 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg. | ||
| CVE-2023-49432 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg. | ||
| CVE-2023-49431 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. | ||
| CVE-2023-49430 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg. | ||
| CVE-2023-49429 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules. | ||
| CVE-2023-49437 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. | ||
| CVE-2023-49428 | Cri | 0.64 | 9.8 | 0.03 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. | ||
| CVE-2023-49426 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg. | ||
| CVE-2023-49425 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg . | ||
| CVE-2023-49424 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg. | ||
| CVE-2023-45484 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGuestBasic. | ||
| CVE-2023-45483 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcontrol_time. | ||
| CVE-2023-45482 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info. | ||
| CVE-2023-45481 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg. | ||
| CVE-2023-45480 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the function sub_47D878. | ||
| CVE-2023-45479 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2023 | Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in the function sub_49E098. | ||
| CVE-2023-49044 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set. | ||
| CVE-2023-49042 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi. | ||
| CVE-2023-49040 | Cri | 0.64 | 9.8 | 0.02 | Nov 27, 2023 | An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function. | ||
| CVE-2023-49046 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2023 | Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule. | ||
| CVE-2023-38823 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2023 | Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd. | ||
| CVE-2023-46369 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | Tenda W18E V16.01.0.8(1576) contains a stack overflow vulnerability via the portMirrorMirroredPorts parameter in the formSetNetCheckTools function. | ||
| CVE-2023-40830 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length. | ||
| CVE-2023-44023 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function. | ||
| CVE-2023-44022 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function. | ||
| CVE-2023-44021 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the formSetClientState function. | ||
| CVE-2023-44020 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function. | ||
| CVE-2023-44019 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the mac parameter in the GetParentControlInfo function. | ||
| CVE-2023-44017 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function. | ||
| CVE-2023-44016 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function. | ||
| CVE-2023-44015 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the setSchedWifi function. | ||
| CVE-2023-44014 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain multiple stack overflows in the formSetMacFilterCfg function via the macFilterType and deviceList parameters. | ||
| CVE-2023-44013 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the list parameter in the fromSetIpMacBind function. | ||
| CVE-2023-42320 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2023 | Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function. | ||
| CVE-2023-40942 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2023 | Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg. |
- risk 0.64cvss 9.8epss 0.02
Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
- risk 0.64cvss 9.8epss 0.01
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.
- risk 0.64cvss 9.8epss 0.02
Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.
- risk 0.64cvss 9.8epss 0.02
Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.
- risk 0.64cvss 9.8epss 0.02
Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 is vulnerable to command injection.
- risk 0.64cvss 9.8epss 0.01
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.01
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- risk 0.64cvss 9.8epss 0.01
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.
- risk 0.64cvss 9.8epss 0.02
Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.
- risk 0.64cvss 9.8epss 0.02
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
- risk 0.64cvss 9.8epss 0.03
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- risk 0.64cvss 9.8epss 0.01
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .
- risk 0.64cvss 9.8epss 0.01
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGuestBasic.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcontrol_time.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the function sub_47D878.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in the function sub_49E098.
- risk 0.64cvss 9.8epss 0.01
Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set.
- risk 0.64cvss 9.8epss 0.01
Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi.
- risk 0.64cvss 9.8epss 0.02
An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function.
- risk 0.64cvss 9.8epss 0.01
Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
- risk 0.64cvss 9.8epss 0.01
Tenda W18E V16.01.0.8(1576) contains a stack overflow vulnerability via the portMirrorMirroredPorts parameter in the formSetNetCheckTools function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the formSetClientState function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the mac parameter in the GetParentControlInfo function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the setSchedWifi function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain multiple stack overflows in the formSetMacFilterCfg function via the macFilterType and deviceList parameters.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the list parameter in the fromSetIpMacBind function.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.
- risk 0.64cvss 9.8epss 0.01
Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg.
Page 6 of 43