tenda CVE Vulnerabilities & Metrics

Focus on tenda vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About tenda Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with tenda. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total tenda CVEs: 966
Earliest CVE date: 22 Aug 2014, 14:55 UTC
Latest CVE date: 04 Mar 2025, 03:15 UTC

Latest CVE reference: CVE-2025-1899

Rolling Stats

30-day Count (Rolling): 3
365-day Count (Rolling): 252

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -62.5%
Year Variation (Calendar): -8.36%

Month Growth Rate (30-day Rolling): -62.5%
Year Growth Rate (365-day Rolling): -8.36%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical tenda CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.37

Max CVSS: 10.0

Critical CVEs (≥9): 237

CVSS Range vs. Count

Range Count
0.0-3.9 583
4.0-6.9 43
7.0-8.9 105
9.0-10.0 237

CVSS Distribution Chart

Top 5 Highest CVSS tenda CVEs

These are the five CVEs with the highest CVSS scores for tenda, sorted by severity first and recency.

All CVEs for tenda

CVE-2025-1899 tenda vulnerability CVSS: 6.8 04 Mar 2025, 03:15 UTC

A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-1895 tenda vulnerability CVSS: 6.8 04 Mar 2025, 02:15 UTC

A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-25343 tenda vulnerability CVSS: 0 12 Feb 2025, 19:15 UTC

Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.

CVE-2025-0848 tenda vulnerability CVSS: 6.8 30 Jan 2025, 02:15 UTC

A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The manipulation of the argument wpapsk_crypto5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-57583 tenda vulnerability CVSS: 0 16 Jan 2025, 21:15 UTC

Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.

CVE-2024-57582 tenda vulnerability CVSS: 0 16 Jan 2025, 21:15 UTC

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.

CVE-2024-57581 tenda vulnerability CVSS: 0 16 Jan 2025, 21:15 UTC

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

CVE-2024-57580 tenda vulnerability CVSS: 0 16 Jan 2025, 21:15 UTC

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

CVE-2024-57579 tenda vulnerability CVSS: 0 16 Jan 2025, 21:15 UTC

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientState function.

CVE-2024-57575 tenda vulnerability CVSS: 0 16 Jan 2025, 21:15 UTC

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVE-2025-0349 tenda vulnerability CVSS: 9.0 09 Jan 2025, 11:15 UTC

A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVE-2024-12002 tenda vulnerability CVSS: 4.0 30 Nov 2024, 13:15 UTC

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11745 tenda vulnerability CVSS: 9.0 26 Nov 2024, 21:15 UTC

A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function route_static_check of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-52714 tenda vulnerability CVSS: 0 19 Nov 2024, 19:15 UTC

Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.

CVE-2024-11248 tenda vulnerability CVSS: 9.0 15 Nov 2024, 17:15 UTC

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11061 tenda vulnerability CVSS: 9.0 11 Nov 2024, 01:15 UTC

A vulnerability classified as critical was found in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function FUN_0044db3c of the file /goform/fast_setting_wifi_set. The manipulation of the argument timeZone leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-11056 tenda vulnerability CVSS: 9.0 10 Nov 2024, 17:15 UTC

A vulnerability, which was classified as critical, was found in Tenda AC10 16.03.10.13. Affected is the function FUN_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10750 tenda vulnerability CVSS: 6.8 04 Nov 2024, 02:15 UTC

A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as problematic. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV?fgHPOST/goform/SysToo. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10698 tenda vulnerability CVSS: 9.0 02 Nov 2024, 14:15 UTC

A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10697 tenda vulnerability CVSS: 6.5 02 Nov 2024, 12:15 UTC

A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument The leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10662 tenda vulnerability CVSS: 9.0 01 Nov 2024, 16:15 UTC

A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10661 tenda vulnerability CVSS: 9.0 01 Nov 2024, 16:15 UTC

A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation of the argument scanList leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10434 tenda vulnerability CVSS: 9.0 28 Oct 2024, 01:15 UTC

A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ate_Tenda_mfg_check_usb/ate_Tenda_mfg_check_usb3 of the file /goform/ate. The manipulation of the argument arg leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10351 tenda vulnerability CVSS: 9.0 25 Oct 2024, 00:15 UTC

A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10283 tenda vulnerability CVSS: 9.0 23 Oct 2024, 15:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda RX9 and RX9 Pro 22.03.02.20. Affected by this issue is the function sub_4337EC of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10282 tenda vulnerability CVSS: 9.0 23 Oct 2024, 15:15 UTC

A vulnerability classified as critical was found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected by this vulnerability is the function sub_42EA38 of the file /goform/SetVirtualServerCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10281 tenda vulnerability CVSS: 9.0 23 Oct 2024, 14:15 UTC

A vulnerability classified as critical has been found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected is the function sub_42EEE0 of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10280 tenda vulnerability CVSS: 6.8 23 Oct 2024, 14:15 UTC

A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10130 tenda vulnerability CVSS: 9.0 18 Oct 2024, 22:15 UTC

A vulnerability classified as critical was found in Tenda AC8 16.03.34.06. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-10123 tenda vulnerability CVSS: 9.0 18 Oct 2024, 20:15 UTC

A vulnerability was found in Tenda AC8 16.03.34.06. It has been declared as critical. Affected by this vulnerability is the function compare_parentcontrol_time of the file /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This is not the same issue like CVE-2023-33671. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-9793 tenda vulnerability CVSS: 6.5 10 Oct 2024, 16:15 UTC

A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-46049 tenda vulnerability CVSS: 0 13 Sep 2024, 14:15 UTC

Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.

CVE-2024-46048 tenda vulnerability CVSS: 0 13 Sep 2024, 14:15 UTC

Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

CVE-2024-46047 tenda vulnerability CVSS: 0 13 Sep 2024, 14:15 UTC

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.

CVE-2024-46046 tenda vulnerability CVSS: 0 13 Sep 2024, 14:15 UTC

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.

CVE-2024-46045 tenda vulnerability CVSS: 0 13 Sep 2024, 14:15 UTC

Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.

CVE-2024-46044 tenda vulnerability CVSS: 0 13 Sep 2024, 14:15 UTC

CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.

CVE-2023-36103 tenda vulnerability CVSS: 0 10 Sep 2024, 16:15 UTC

Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.

CVE-2024-8231 tenda vulnerability CVSS: 9.0 28 Aug 2024, 02:15 UTC

A vulnerability classified as critical has been found in Tenda O6 1.0.0.7(2054). Affected is the function fromVirtualSet of the file /goform/setPortForward. The manipulation of the argument ip/localPort/publicPort/app leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8230 tenda vulnerability CVSS: 9.0 28 Aug 2024, 02:15 UTC

A vulnerability was found in Tenda O6 1.0.0.7(2054). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation of the argument remark/type/time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8229 tenda vulnerability CVSS: 9.0 28 Aug 2024, 01:15 UTC

A vulnerability was found in Tenda O6 1.0.0.7(2054). It has been declared as critical. This vulnerability affects the function frommacFilterModify of the file /goform/operateMacFilter. The manipulation of the argument mac leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8228 tenda vulnerability CVSS: 9.0 28 Aug 2024, 00:15 UTC

A vulnerability was found in Tenda O5 1.0.0.8(5017). It has been classified as critical. This affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation of the argument remark/type/time leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8227 tenda vulnerability CVSS: 9.0 28 Aug 2024, 00:15 UTC

A vulnerability was found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this issue is the function fromDhcpSetSer of the file /goform/DhcpSetSer. The manipulation of the argument dhcpStartIp/dhcpEndIp/dhcpGw/dhcpMask/dhcpLeaseTime/dhcpDns1/dhcpDns2 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8226 tenda vulnerability CVSS: 9.0 28 Aug 2024, 00:15 UTC

A vulnerability has been found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8225 tenda vulnerability CVSS: 9.0 27 Aug 2024, 23:15 UTC

A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument sysTimePolicy leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-44557 tenda vulnerability CVSS: 0 26 Aug 2024, 16:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.

CVE-2024-44555 tenda vulnerability CVSS: 0 26 Aug 2024, 16:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.

CVE-2024-44553 tenda vulnerability CVSS: 0 26 Aug 2024, 16:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

CVE-2024-44552 tenda vulnerability CVSS: 0 26 Aug 2024, 16:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.

CVE-2024-44551 tenda vulnerability CVSS: 0 26 Aug 2024, 16:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.

CVE-2024-44550 tenda vulnerability CVSS: 0 26 Aug 2024, 16:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

CVE-2024-44549 tenda vulnerability CVSS: 0 26 Aug 2024, 16:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.

CVE-2024-44558 tenda vulnerability CVSS: 0 26 Aug 2024, 13:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.

CVE-2024-44556 tenda vulnerability CVSS: 0 26 Aug 2024, 13:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.

CVE-2024-44565 tenda vulnerability CVSS: 0 26 Aug 2024, 12:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.

CVE-2024-44563 tenda vulnerability CVSS: 0 26 Aug 2024, 12:15 UTC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.

CVE-2024-44390 tenda vulnerability CVSS: 0 23 Aug 2024, 17:15 UTC

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.

CVE-2024-44387 tenda vulnerability CVSS: 0 23 Aug 2024, 17:15 UTC

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.

CVE-2024-42987 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the modino parameter in the fromPptpUserAdd function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42986 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42985 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42984 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42983 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the pptpPPW parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42982 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42981 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42980 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42979 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ProtForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42978 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.

CVE-2024-42977 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42976 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42974 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42973 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42969 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42968 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the Go parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42955 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42952 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42951 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42950 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42948 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42947 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.

CVE-2024-42946 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42944 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42943 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42941 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-42940 tenda vulnerability CVSS: 0 15 Aug 2024, 17:15 UTC

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-7707 tenda vulnerability CVSS: 9.0 13 Aug 2024, 01:24 UTC

A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function formSafeEmailFilter of the file /goform/SafeEmailFilter of the component HTTP POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7615 tenda vulnerability CVSS: 9.0 12 Aug 2024, 13:38 UTC

A vulnerability was found in Tenda FH1206 1.2.0.8. It has been declared as critical. Affected by this vulnerability is the function fromSafeClientFilter/fromSafeMacFilter/fromSafeUrlFilter. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7614 tenda vulnerability CVSS: 9.0 12 Aug 2024, 13:38 UTC

A vulnerability was found in Tenda FH1206 1.2.0.8(8155). It has been classified as critical. Affected is the function fromqossetting of the file /goform/qossetting. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7613 tenda vulnerability CVSS: 9.0 12 Aug 2024, 13:38 UTC

A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of the argument dips leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7585 tenda vulnerability CVSS: 9.0 07 Aug 2024, 17:15 UTC

A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as critical. Affected by this vulnerability is the function formApPortalWebAuth of the file /goform/apPortalAuth. The manipulation of the argument webUserName/webUserPassword leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7584 tenda vulnerability CVSS: 9.0 07 Aug 2024, 17:15 UTC

A vulnerability, which was classified as critical, was found in Tenda i22 1.0.0.3(4687). Affected is the function formApPortalPhoneAuth of the file /goform/apPortalPhoneAuth. The manipulation of the argument data leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7583 tenda vulnerability CVSS: 9.0 07 Aug 2024, 16:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda i22 1.0.0.3(4687). This issue affects the function formApPortalOneKeyAuth of the file /goform/apPortalOneKeyAuth. The manipulation of the argument data leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7582 tenda vulnerability CVSS: 9.0 07 Aug 2024, 16:15 UTC

A vulnerability classified as critical was found in Tenda i22 1.0.0.3(4687). This vulnerability affects the function formApPortalAccessCodeAuth of the file /goform/apPortalAccessCodeAuth. The manipulation of the argument accessCode/data/acceInfo leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7152 tenda vulnerability CVSS: 9.0 27 Jul 2024, 21:15 UTC

A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation of the argument time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272555. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7151 tenda vulnerability CVSS: 9.0 27 Jul 2024, 20:15 UTC

A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been declared as critical. This vulnerability affects the function fromMacFilterSet of the file /goform/setMacFilter. The manipulation of the argument remark leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-272554 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-6965 tenda vulnerability CVSS: 9.0 22 Jul 2024, 02:15 UTC

A vulnerability has been found in Tenda O3 1.0.0.10 and classified as critical. Affected by this vulnerability is the function fromVirtualSet. The manipulation of the argument ip/localPort/publicPort/app leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272119. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-6964 tenda vulnerability CVSS: 9.0 22 Jul 2024, 02:15 UTC

A vulnerability, which was classified as critical, was found in Tenda O3 1.0.0.10. Affected is the function fromDhcpSetSer. The manipulation of the argument dhcpEn/startIP/endIP/preDNS/altDNS/mask/gateway leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272118 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-6963 tenda vulnerability CVSS: 9.0 22 Jul 2024, 00:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda O3 1.0.0.10. This issue affects the function formexeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272117 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-6962 tenda vulnerability CVSS: 9.0 22 Jul 2024, 00:15 UTC

A vulnerability classified as critical was found in Tenda O3 1.0.0.10. This vulnerability affects the function formQosSet. The manipulation of the argument remark/ipRange/upSpeed/downSpeed/enable leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272116. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-40416 tenda vulnerability CVSS: 0 15 Jul 2024, 18:15 UTC

A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

CVE-2024-40415 tenda vulnerability CVSS: 0 15 Jul 2024, 18:15 UTC

A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

CVE-2024-40414 tenda vulnerability CVSS: 0 15 Jul 2024, 17:15 UTC

A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

CVE-2023-48194 tenda vulnerability CVSS: 0 09 Jul 2024, 18:15 UTC

Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained.

CVE-2024-36604 tenda vulnerability CVSS: 0 04 Jun 2024, 19:20 UTC

Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.

CVE-2024-4497 tenda vulnerability CVSS: 9.0 05 May 2024, 07:15 UTC

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been declared as critical. This vulnerability affects the function formexeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263086 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4496 tenda vulnerability CVSS: 9.0 05 May 2024, 06:15 UTC

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been classified as critical. This affects the function formWifiMacFilterSet. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263085 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4495 tenda vulnerability CVSS: 9.0 05 May 2024, 06:15 UTC

A vulnerability was found in Tenda i21 1.0.0.14(4656) and classified as critical. Affected by this issue is the function formWifiMacFilterGet. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263084. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4494 tenda vulnerability CVSS: 9.0 05 May 2024, 05:15 UTC

A vulnerability has been found in Tenda i21 1.0.0.14(4656) and classified as critical. Affected by this vulnerability is the function formSetUplinkInfo of the file /goform/setUplinkInfo. The manipulation of the argument pingHostIp2 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263083. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4493 tenda vulnerability CVSS: 9.0 05 May 2024, 03:15 UTC

A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). Affected is the function formSetAutoPing. The manipulation of the argument ping1/ping2 leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263082 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4492 tenda vulnerability CVSS: 9.0 05 May 2024, 01:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). This issue affects the function formOfflineSet of the file /goform/setStaOffline. The manipulation of the argument GO/ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263081 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4491 tenda vulnerability CVSS: 9.0 05 May 2024, 00:15 UTC

A vulnerability classified as critical was found in Tenda i21 1.0.0.14(4656). This vulnerability affects the function formGetDiagnoseInfo. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263080. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4252 tenda vulnerability CVSS: 9.0 27 Apr 2024, 14:15 UTC

A vulnerability classified as critical has been found in Tenda i22 1.0.0.3(4687). This affects the function formSetUrlFilterRule. The manipulation of the argument groupIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-262143. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4251 tenda vulnerability CVSS: 9.0 27 Apr 2024, 13:15 UTC

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been rated as critical. Affected by this issue is the function fromDhcpSetSer of the file /goform/DhcpSetSe. The manipulation of the argument dhcpStartIp/dhcpEndIp/dhcpGw/dhcpMask/dhcpLeaseTime/dhcpDns1/dhcpDns2 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-262142 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4250 tenda vulnerability CVSS: 9.0 27 Apr 2024, 12:15 UTC

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been declared as critical. Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262141 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4249 tenda vulnerability CVSS: 9.0 27 Apr 2024, 12:15 UTC

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been classified as critical. Affected is the function formwrlSSIDget of the file /goform/wifiSSIDget. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262140. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4248 tenda vulnerability CVSS: 9.0 27 Apr 2024, 11:15 UTC

A vulnerability was found in Tenda i21 1.0.0.14(4656) and classified as critical. This issue affects the function formQosManage_user. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-262139. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4247 tenda vulnerability CVSS: 9.0 27 Apr 2024, 10:15 UTC

A vulnerability has been found in Tenda i21 1.0.0.14(4656) and classified as critical. This vulnerability affects the function formQosManage_auto. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack can be initiated remotely. VDB-262138 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4246 tenda vulnerability CVSS: 9.0 27 Apr 2024, 09:15 UTC

A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). This affects the function formQosManageDouble_auto. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The identifier VDB-262137 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4245 tenda vulnerability CVSS: 9.0 27 Apr 2024, 08:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). Affected by this issue is the function formQosManageDouble_user. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be launched remotely. The identifier of this vulnerability is VDB-262136. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4244 tenda vulnerability CVSS: 9.0 26 Apr 2024, 22:15 UTC

A vulnerability classified as critical was found in Tenda W9 1.0.0.7(4456). Affected by this vulnerability is the function fromDhcpSetSer of the file /goform/DhcpSetSer. The manipulation of the argument dhcpStartIp/dhcpEndIp/dhcpGw/dhcpMask/dhcpLeaseTime/dhcpDns1/dhcpDns2 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-262135. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4243 tenda vulnerability CVSS: 9.0 26 Apr 2024, 22:15 UTC

A vulnerability classified as critical has been found in Tenda W9 1.0.0.7(4456). Affected is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-262134 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4242 tenda vulnerability CVSS: 9.0 26 Apr 2024, 21:15 UTC

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function formwrlSSIDget of the file /goform/wifiSSIDget. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4241 tenda vulnerability CVSS: 9.0 26 Apr 2024, 21:15 UTC

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. This vulnerability affects the function formQosManageDouble_auto. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack can be initiated remotely. The identifier of this vulnerability is VDB-262132. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4240 tenda vulnerability CVSS: 9.0 26 Apr 2024, 21:15 UTC

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. This affects the function formQosManageDouble_user. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-262131. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4239 tenda vulnerability CVSS: 9.0 26 Apr 2024, 21:15 UTC

A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-262130 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4238 tenda vulnerability CVSS: 9.0 26 Apr 2024, 20:15 UTC

A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262129 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4237 tenda vulnerability CVSS: 9.0 26 Apr 2024, 19:15 UTC

A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262128. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4170 tenda vulnerability CVSS: 9.0 25 Apr 2024, 13:15 UTC

A vulnerability was found in Tenda 4G300 1.01.42. It has been rated as critical. This issue affects the function sub_429A30. The manipulation of the argument list1 leads to stack-based buffer overflow. The attack may be initiated remotely. The identifier VDB-261989 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4169 tenda vulnerability CVSS: 9.0 25 Apr 2024, 13:15 UTC

A vulnerability was found in Tenda 4G300 1.01.42. It has been declared as critical. This vulnerability affects the function sub_42775C/sub_4279CC. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely. The identifier of this vulnerability is VDB-261988. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4168 tenda vulnerability CVSS: 9.0 25 Apr 2024, 12:15 UTC

A vulnerability was found in Tenda 4G300 1.01.42. It has been classified as critical. This affects the function sub_4260F0. The manipulation of the argument upfilen leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-261987. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4167 tenda vulnerability CVSS: 9.0 25 Apr 2024, 12:15 UTC

A vulnerability was found in Tenda 4G300 1.01.42 and classified as critical. Affected by this issue is the function sub_422AA4. The manipulation of the argument year/month/day/hour/minute/second leads to stack-based buffer overflow. The attack may be launched remotely. VDB-261986 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4166 tenda vulnerability CVSS: 9.0 25 Apr 2024, 12:15 UTC

A vulnerability has been found in Tenda 4G300 1.01.42 and classified as critical. Affected by this vulnerability is the function sub_41E858. The manipulation of the argument GO/page leads to stack-based buffer overflow. The attack can be launched remotely. The identifier VDB-261985 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4127 tenda vulnerability CVSS: 9.0 24 Apr 2024, 20:15 UTC

A vulnerability was found in Tenda W15E 15.11.0.14. It has been classified as critical. Affected is the function guestWifiRuleRefresh. The manipulation of the argument qosGuestDownstream leads to stack-based buffer overflow. It is possible to launch the attack remotely. VDB-261870 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4126 tenda vulnerability CVSS: 9.0 24 Apr 2024, 20:15 UTC

A vulnerability was found in Tenda W15E 15.11.0.14 and classified as critical. This issue affects the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument manualTime leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261869 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4125 tenda vulnerability CVSS: 9.0 24 Apr 2024, 19:15 UTC

A vulnerability has been found in Tenda W15E 15.11.0.14 and classified as critical. This vulnerability affects the function formSetStaticRoute of the file /goform/setStaticRoute. The manipulation of the argument staticRouteIndex leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261868. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4124 tenda vulnerability CVSS: 9.0 24 Apr 2024, 19:15 UTC

A vulnerability, which was classified as critical, was found in Tenda W15E 15.11.0.14. This affects the function formSetRemoteWebManage of the file /goform/SetRemoteWebManage. The manipulation of the argument remoteIP leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261867. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4123 tenda vulnerability CVSS: 9.0 24 Apr 2024, 19:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda W15E 15.11.0.14. Affected by this issue is the function formSetPortMapping of the file /goform/SetPortMapping. The manipulation of the argument portMappingServer/portMappingProtocol/portMappingWan/porMappingtInternal/portMappingExternal leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-261866 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4122 tenda vulnerability CVSS: 9.0 24 Apr 2024, 18:15 UTC

A vulnerability classified as critical was found in Tenda W15E 15.11.0.14. Affected by this vulnerability is the function formSetDebugCfg of the file /goform/setDebugCfg. The manipulation of the argument enable/level/module leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261865 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4121 tenda vulnerability CVSS: 9.0 24 Apr 2024, 18:15 UTC

A vulnerability classified as critical has been found in Tenda W15E 15.11.0.14. Affected is the function formQOSRuleDel. The manipulation of the argument qosIndex leads to stack-based buffer overflow. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-261864. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4120 tenda vulnerability CVSS: 9.0 24 Apr 2024, 18:15 UTC

A vulnerability was found in Tenda W15E 15.11.0.14. It has been rated as critical. This issue affects the function formIPMacBindModify of the file /goform/modifyIpMacBind. The manipulation of the argument IPMacBindRuleId/IPMacBindRuleIp/IPMacBindRuleMac/IPMacBindRuleRemark leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261863. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4119 tenda vulnerability CVSS: 9.0 24 Apr 2024, 17:15 UTC

A vulnerability was found in Tenda W15E 15.11.0.14. It has been declared as critical. This vulnerability affects the function formIPMacBindDel of the file /goform/delIpMacBind. The manipulation of the argument IPMacBindIndex leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-261862 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4118 tenda vulnerability CVSS: 9.0 24 Apr 2024, 17:15 UTC

A vulnerability was found in Tenda W15E 15.11.0.14. It has been classified as critical. This affects the function formIPMacBindAdd of the file /goform/addIpMacBind. The manipulation of the argument IPMacBindRule leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261861 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4117 tenda vulnerability CVSS: 9.0 24 Apr 2024, 16:15 UTC

A vulnerability was found in Tenda W15E 15.11.0.14 and classified as critical. Affected by this issue is the function formDelPortMapping of the file /goform/DelPortMapping. The manipulation of the argument portMappingIndex leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261860. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4116 tenda vulnerability CVSS: 9.0 24 Apr 2024, 16:15 UTC

A vulnerability has been found in Tenda W15E 15.11.0.14 and classified as critical. Affected by this vulnerability is the function formDelDhcpRule of the file /goform/DelDhcpRule. The manipulation of the argument delDhcpIndex leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261859. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4115 tenda vulnerability CVSS: 9.0 24 Apr 2024, 16:15 UTC

A vulnerability, which was classified as critical, was found in Tenda W15E 15.11.0.14. Affected is the function formAddDnsForward of the file /goform/AddDnsForward. The manipulation of the argument DnsForwardRule leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-261858 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4114 tenda vulnerability CVSS: 9.0 24 Apr 2024, 15:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda TX9 22.03.02.10. This issue affects the function sub_42C014 of the file /goform/PowerSaveSet. The manipulation of the argument time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261857 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4113 tenda vulnerability CVSS: 9.0 24 Apr 2024, 15:15 UTC

A vulnerability classified as critical was found in Tenda TX9 22.03.02.10. This vulnerability affects the function sub_42D4DC of the file /goform/SetSysTimeCfg. The manipulation of the argument time leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261856. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4112 tenda vulnerability CVSS: 9.0 24 Apr 2024, 15:15 UTC

A vulnerability classified as critical has been found in Tenda TX9 22.03.02.10. This affects the function sub_42CB94 of the file /goform/SetVirtualServerCfg. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261855. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4111 tenda vulnerability CVSS: 9.0 24 Apr 2024, 14:15 UTC

A vulnerability was found in Tenda TX9 22.03.02.10. It has been rated as critical. Affected by this issue is the function sub_42BD7C of the file /goform/SetLEDCfg. The manipulation of the argument time leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-261854 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4066 tenda vulnerability CVSS: 9.0 23 Apr 2024, 21:15 UTC

A vulnerability classified as critical has been found in Tenda AC8 16.03.34.09. Affected is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The manipulation of the argument wanMTU/wanSpeed/cloneType/mac/serviceName/serverName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261792. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4065 tenda vulnerability CVSS: 9.0 23 Apr 2024, 20:15 UTC

A vulnerability was found in Tenda AC8 16.03.34.09. It has been rated as critical. This issue affects the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261791. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4064 tenda vulnerability CVSS: 9.0 23 Apr 2024, 20:15 UTC

A vulnerability was found in Tenda AC8 16.03.34.09. It has been declared as critical. This vulnerability affects the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-261790 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3910 tenda vulnerability CVSS: 9.0 17 Apr 2024, 12:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda AC500 2.0.1.9(1307). Affected by this issue is the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-261146 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3909 tenda vulnerability CVSS: 9.0 17 Apr 2024, 12:15 UTC

A vulnerability classified as critical was found in Tenda AC500 2.0.1.9(1307). Affected by this vulnerability is the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261145 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3908 tenda vulnerability CVSS: 6.5 17 Apr 2024, 12:15 UTC

A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261144. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3907 tenda vulnerability CVSS: 9.0 17 Apr 2024, 11:15 UTC

A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been rated as critical. This issue affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261143. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3906 tenda vulnerability CVSS: 9.0 17 Apr 2024, 11:15 UTC

A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-261142 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3905 tenda vulnerability CVSS: 9.0 17 Apr 2024, 11:15 UTC

A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been classified as critical. This affects the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261141 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3882 tenda vulnerability CVSS: 9.0 16 Apr 2024, 20:15 UTC

A vulnerability was found in Tenda W30E 1.0.1.25(633). It has been classified as critical. Affected is the function fromRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260916. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3881 tenda vulnerability CVSS: 9.0 16 Apr 2024, 20:15 UTC

A vulnerability was found in Tenda W30E 1.0.1.25(633) and classified as critical. This issue affects the function frmL7PlotForm of the file /goform/frmL7ProtForm. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260915. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3880 tenda vulnerability CVSS: 6.5 16 Apr 2024, 19:15 UTC

A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-260914 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3879 tenda vulnerability CVSS: 9.0 16 Apr 2024, 19:15 UTC

A vulnerability, which was classified as critical, was found in Tenda W30E 1.0.1.25(633). This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260913 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3878 tenda vulnerability CVSS: 9.0 16 Apr 2024, 19:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda F1202 1.2.0.20(408). Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260912. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3877 tenda vulnerability CVSS: 9.0 16 Apr 2024, 19:15 UTC

A vulnerability classified as critical was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function fromqossetting of the file /goform/fromqossetting. The manipulation of the argument qos leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260911. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3876 tenda vulnerability CVSS: 9.0 16 Apr 2024, 18:15 UTC

A vulnerability classified as critical has been found in Tenda F1202 1.2.0.20(408). Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-260910 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3875 tenda vulnerability CVSS: 9.0 16 Apr 2024, 18:15 UTC

A vulnerability was found in Tenda F1202 1.2.0.20(408). It has been rated as critical. This issue affects the function fromNatlimit of the file /goform/Natlimit. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260909 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-30621 tenda vulnerability CVSS: 0 02 Apr 2024, 14:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.

CVE-2024-30620 tenda vulnerability CVSS: 0 02 Apr 2024, 14:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.

CVE-2024-3012 tenda vulnerability CVSS: 9.0 28 Mar 2024, 00:15 UTC

A vulnerability was found in Tenda FH1205 2.0.0.7(775). It has been declared as critical. This vulnerability affects the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258298 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3011 tenda vulnerability CVSS: 9.0 28 Mar 2024, 00:15 UTC

A vulnerability was found in Tenda FH1205 2.0.0.7(775). It has been classified as critical. This affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258297 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3010 tenda vulnerability CVSS: 9.0 28 Mar 2024, 00:15 UTC

A vulnerability was found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this issue is the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258296. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3009 tenda vulnerability CVSS: 6.5 28 Mar 2024, 00:15 UTC

A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258295. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3008 tenda vulnerability CVSS: 9.0 27 Mar 2024, 23:15 UTC

A vulnerability, which was classified as critical, was found in Tenda FH1205 2.0.0.7(775). Affected is the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258294 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3007 tenda vulnerability CVSS: 9.0 27 Mar 2024, 23:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7(775). This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258293 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-3006 tenda vulnerability CVSS: 9.0 27 Mar 2024, 23:15 UTC

A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromSetRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument entrys leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258292. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2994 tenda vulnerability CVSS: 9.0 27 Mar 2024, 20:15 UTC

A vulnerability was found in Tenda FH1203 2.0.1.6. It has been declared as critical. Affected by this vulnerability is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258163. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2993 tenda vulnerability CVSS: 9.0 27 Mar 2024, 20:15 UTC

A vulnerability was found in Tenda FH1203 2.0.1.6. It has been classified as critical. Affected is the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2992 tenda vulnerability CVSS: 9.0 27 Mar 2024, 19:15 UTC

A vulnerability was found in Tenda FH1203 2.0.1.6 and classified as critical. This issue affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2991 tenda vulnerability CVSS: 6.5 27 Mar 2024, 19:15 UTC

A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258160. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2990 tenda vulnerability CVSS: 9.0 27 Mar 2024, 19:15 UTC

A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. This affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258159. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2989 tenda vulnerability CVSS: 9.0 27 Mar 2024, 18:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda FH1203 2.0.1.6. Affected by this issue is the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-258158 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2988 tenda vulnerability CVSS: 9.0 27 Mar 2024, 18:15 UTC

A vulnerability classified as critical was found in Tenda FH1203 2.0.1.6. Affected by this vulnerability is the function fromSetRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument entrys leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258157 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2987 tenda vulnerability CVSS: 9.0 27 Mar 2024, 17:15 UTC

A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258156. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2986 tenda vulnerability CVSS: 9.0 27 Mar 2024, 17:15 UTC

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258155. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2985 tenda vulnerability CVSS: 9.0 27 Mar 2024, 17:15 UTC

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258154 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2984 tenda vulnerability CVSS: 9.0 27 Mar 2024, 16:15 UTC

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been classified as critical. This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258153 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2983 tenda vulnerability CVSS: 9.0 27 Mar 2024, 16:15 UTC

A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this issue is the function formSetClientState of the file /goform/SetClientState. The manipulation of the argument deviceId/limitSpeed/limitSpeedUp leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258152. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2982 tenda vulnerability CVSS: 5.2 27 Mar 2024, 16:15 UTC

A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258151. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2981 tenda vulnerability CVSS: 9.0 27 Mar 2024, 15:15 UTC

A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258150 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2980 tenda vulnerability CVSS: 9.0 27 Mar 2024, 15:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258149 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2979 tenda vulnerability CVSS: 9.0 27 Mar 2024, 14:15 UTC

A vulnerability classified as critical was found in Tenda F1203 2.0.1.6. This vulnerability affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258148. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2978 tenda vulnerability CVSS: 9.0 27 Mar 2024, 14:15 UTC

A vulnerability classified as critical has been found in Tenda F1203 2.0.1.6. This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258147. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2977 tenda vulnerability CVSS: 9.0 27 Mar 2024, 14:15 UTC

A vulnerability was found in Tenda F1203 2.0.1.6. It has been rated as critical. Affected by this issue is the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-258146 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2976 tenda vulnerability CVSS: 9.0 27 Mar 2024, 14:15 UTC

A vulnerability was found in Tenda F1203 2.0.1.6. It has been declared as critical. Affected by this vulnerability is the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258145 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2903 tenda vulnerability CVSS: 9.0 26 Mar 2024, 21:15 UTC

A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257946 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2902 tenda vulnerability CVSS: 9.0 26 Mar 2024, 20:15 UTC

A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. The manipulation of the argument shareSpeed leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257945 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2901 tenda vulnerability CVSS: 9.0 26 Mar 2024, 20:15 UTC

A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. This vulnerability affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257944. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2900 tenda vulnerability CVSS: 9.0 26 Mar 2024, 20:15 UTC

A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. This affects the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257943. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2899 tenda vulnerability CVSS: 9.0 26 Mar 2024, 19:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257942 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2898 tenda vulnerability CVSS: 9.0 26 Mar 2024, 19:15 UTC

A vulnerability classified as critical was found in Tenda AC7 15.03.06.44. Affected by this vulnerability is the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257941 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2897 tenda vulnerability CVSS: 6.5 26 Mar 2024, 19:15 UTC

A vulnerability classified as critical has been found in Tenda AC7 15.03.06.44. Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257940. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2896 tenda vulnerability CVSS: 9.0 26 Mar 2024, 18:15 UTC

A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. This issue affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257939. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2895 tenda vulnerability CVSS: 9.0 26 Mar 2024, 18:15 UTC

A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. This vulnerability affects the function formWifiWpsOOB of the file /goform/WifiWpsOOB. The manipulation of the argument index leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257938 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2894 tenda vulnerability CVSS: 9.0 26 Mar 2024, 17:15 UTC

A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. This affects the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257937 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2893 tenda vulnerability CVSS: 9.0 26 Mar 2024, 17:15 UTC

A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257936. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2892 tenda vulnerability CVSS: 9.0 26 Mar 2024, 16:15 UTC

A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257935. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2891 tenda vulnerability CVSS: 9.0 26 Mar 2024, 14:15 UTC

A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. Affected is the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257934 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2856 tenda vulnerability CVSS: 9.0 24 Mar 2024, 07:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257780. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2855 tenda vulnerability CVSS: 9.0 24 Mar 2024, 06:15 UTC

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20. Affected by this vulnerability is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257779. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2854 tenda vulnerability CVSS: 6.5 24 Mar 2024, 06:15 UTC

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetSambaConf of the file /goform/setsambacfg. The manipulation of the argument usbName leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257778 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2853 tenda vulnerability CVSS: 6.5 24 Mar 2024, 05:15 UTC

A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. It has been rated as critical. This issue affects the function formSetSambaConf of the file /goform/setsambacfg. The manipulation of the argument usbName leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257777 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2852 tenda vulnerability CVSS: 9.0 24 Mar 2024, 05:15 UTC

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257776. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2851 tenda vulnerability CVSS: 6.5 24 Mar 2024, 03:15 UTC

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formSetSambaConf of the file /goform/setsambacfg. The manipulation of the argument usbName leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257775. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2850 tenda vulnerability CVSS: 9.0 24 Mar 2024, 02:15 UTC

A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257774 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2817 tenda vulnerability CVSS: 5.0 22 Mar 2024, 08:15 UTC

A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. Affected by this issue is the function fromSysToolRestoreSet of the file /goform/SysToolRestoreSet. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257672. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2816 tenda vulnerability CVSS: 5.0 22 Mar 2024, 08:15 UTC

A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. Affected by this vulnerability is the function fromSysToolReboot of the file /goform/SysToolReboot. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257671. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2815 tenda vulnerability CVSS: 9.0 22 Mar 2024, 08:15 UTC

A vulnerability classified as critical has been found in Tenda AC15 15.03.20_multi. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand of the component Cookie Handler. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257670 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2814 tenda vulnerability CVSS: 9.0 22 Mar 2024, 07:15 UTC

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been rated as critical. This issue affects the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257669 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2813 tenda vulnerability CVSS: 9.0 22 Mar 2024, 07:15 UTC

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257668. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2812 tenda vulnerability CVSS: 6.5 22 Mar 2024, 07:15 UTC

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257667. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2811 tenda vulnerability CVSS: 9.0 22 Mar 2024, 06:15 UTC

A vulnerability was found in Tenda AC15 15.03.20_multi and classified as critical. Affected by this issue is the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257666 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2810 tenda vulnerability CVSS: 9.0 22 Mar 2024, 06:15 UTC

A vulnerability has been found in Tenda AC15 15.03.05.18/15.03.20_multi and classified as critical. Affected by this vulnerability is the function formWifiWpsOOB of the file /goform/WifiWpsOOB. The manipulation of the argument index leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257665 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2809 tenda vulnerability CVSS: 9.0 22 Mar 2024, 06:15 UTC

A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20_multi. Affected is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257664. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2808 tenda vulnerability CVSS: 9.0 22 Mar 2024, 05:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This issue affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257663. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2807 tenda vulnerability CVSS: 9.0 22 Mar 2024, 05:15 UTC

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi. This vulnerability affects the function formExpandDlnaFile of the file /goform/expandDlnaFile. The manipulation of the argument filePath leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257662 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2806 tenda vulnerability CVSS: 9.0 22 Mar 2024, 05:15 UTC

A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This affects the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the argument deviceId/deviceMac leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257661 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2805 tenda vulnerability CVSS: 9.0 22 Mar 2024, 03:15 UTC

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257660. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2764 tenda vulnerability CVSS: 9.0 21 Mar 2024, 21:15 UTC

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument endIP leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257601 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2763 tenda vulnerability CVSS: 9.0 21 Mar 2024, 21:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is the function formSetCfm of the file goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257600. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2711 tenda vulnerability CVSS: 9.0 20 Mar 2024, 18:15 UTC

A vulnerability was found in Tenda AC10U 15.03.06.48. It has been rated as critical. Affected by this issue is the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the argument deviceMac leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257462 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2710 tenda vulnerability CVSS: 9.0 20 Mar 2024, 18:15 UTC

A vulnerability was found in Tenda AC10U 15.03.06.49. It has been declared as critical. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257461 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2709 tenda vulnerability CVSS: 9.0 20 Mar 2024, 18:15 UTC

A vulnerability was found in Tenda AC10U 15.03.06.49. It has been classified as critical. Affected is the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257460. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2708 tenda vulnerability CVSS: 9.0 20 Mar 2024, 18:15 UTC

A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical. This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257459. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2707 tenda vulnerability CVSS: 6.5 20 Mar 2024, 17:15 UTC

A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257458 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2706 tenda vulnerability CVSS: 9.0 20 Mar 2024, 17:15 UTC

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49. This affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of the argument index leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257457 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2705 tenda vulnerability CVSS: 9.0 20 Mar 2024, 17:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49. Affected by this issue is the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257456. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2704 tenda vulnerability CVSS: 9.0 20 Mar 2024, 16:15 UTC

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49. Affected by this vulnerability is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257455. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2703 tenda vulnerability CVSS: 9.0 20 Mar 2024, 16:15 UTC

A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49. Affected is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257454 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2581 tenda vulnerability CVSS: 9.0 18 Mar 2024, 03:15 UTC

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257081 was assigned to this vulnerability.

CVE-2024-2560 tenda vulnerability CVSS: 5.0 17 Mar 2024, 11:15 UTC

A vulnerability classified as problematic was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function fromSysToolRestoreSet of the file /goform/SysToolRestoreSet. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257059. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2559 tenda vulnerability CVSS: 5.0 17 Mar 2024, 10:15 UTC

A vulnerability classified as problematic has been found in Tenda AC18 15.03.05.05. Affected is the function fromSysToolReboot of the file /goform/SysToolReboot. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257058 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2558 tenda vulnerability CVSS: 9.0 17 Mar 2024, 09:15 UTC

A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257057 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2547 tenda vulnerability CVSS: 9.0 17 Mar 2024, 04:15 UTC

A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function R7WebsSecurityHandler. The manipulation of the argument password leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257000. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2546 tenda vulnerability CVSS: 9.0 17 Mar 2024, 02:15 UTC

A vulnerability has been found in Tenda AC18 15.13.07.09 and classified as critical. Affected by this vulnerability is the function fromSetWirelessRepeat. The manipulation of the argument wpapsk_crypto5g leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256999. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2490 tenda vulnerability CVSS: 9.0 15 Mar 2024, 10:15 UTC

A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256897 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2489 tenda vulnerability CVSS: 9.0 15 Mar 2024, 09:15 UTC

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256896. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2488 tenda vulnerability CVSS: 9.0 15 Mar 2024, 09:15 UTC

A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIP leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256895. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2487 tenda vulnerability CVSS: 9.0 15 Mar 2024, 09:15 UTC

A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName/mac leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-256894 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2486 tenda vulnerability CVSS: 9.0 15 Mar 2024, 08:15 UTC

A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256893 was assigned to this vulnerability.

CVE-2024-2485 tenda vulnerability CVSS: 9.0 15 Mar 2024, 07:15 UTC

A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256892. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-28553 tenda vulnerability CVSS: 0 12 Mar 2024, 13:15 UTC

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.

CVE-2024-28535 tenda vulnerability CVSS: 0 12 Mar 2024, 13:15 UTC

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.

CVE-2024-24543 tenda vulnerability CVSS: 0 05 Feb 2024, 21:15 UTC

Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.

CVE-2024-0996 tenda vulnerability CVSS: 8.3 29 Jan 2024, 03:15 UTC

A vulnerability classified as critical has been found in Tenda i9 1.0.0.9(4122). This affects the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252261 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0995 tenda vulnerability CVSS: 8.3 29 Jan 2024, 02:15 UTC

A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been rated as critical. Affected by this issue is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252260. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0994 tenda vulnerability CVSS: 8.3 29 Jan 2024, 02:15 UTC

A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been declared as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252259. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0993 tenda vulnerability CVSS: 8.3 29 Jan 2024, 02:15 UTC

A vulnerability was found in Tenda i6 1.0.0.9(3857). It has been classified as critical. Affected is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-252258 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0992 tenda vulnerability CVSS: 8.3 29 Jan 2024, 01:15 UTC

A vulnerability was found in Tenda i6 1.0.0.9(3857) and classified as critical. This issue affects the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252257 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0991 tenda vulnerability CVSS: 8.3 29 Jan 2024, 01:15 UTC

A vulnerability has been found in Tenda i6 1.0.0.9(3857) and classified as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252256. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0990 tenda vulnerability CVSS: 8.3 29 Jan 2024, 01:15 UTC

A vulnerability, which was classified as critical, was found in Tenda i6 1.0.0.9(3857). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component httpd. The manipulation of the argument ping1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0924 tenda vulnerability CVSS: 5.8 26 Jan 2024, 15:15 UTC

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function formSetPPTPServer. The manipulation of the argument startIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252129 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0542 tenda vulnerability CVSS: 9.0 15 Jan 2024, 05:15 UTC

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. Affected by this issue is the function formWifiMacFilterGet of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250712. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0541 tenda vulnerability CVSS: 9.0 15 Jan 2024, 05:15 UTC

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. Affected by this vulnerability is the function formAddSysLogRule of the component httpd. The manipulation of the argument sysRulenEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250711. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0540 tenda vulnerability CVSS: 6.5 15 Jan 2024, 05:15 UTC

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. Affected is the function formOfflineSet of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250710 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0539 tenda vulnerability CVSS: 9.0 15 Jan 2024, 05:15 UTC

A vulnerability was found in Tenda W9 1.0.0.7(4456) and classified as critical. This issue affects the function formQosManage_user of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250709 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0538 tenda vulnerability CVSS: 9.0 15 Jan 2024, 04:15 UTC

A vulnerability has been found in Tenda W9 1.0.0.7(4456) and classified as critical. This vulnerability affects the function formQosManage_auto of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250708. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0537 tenda vulnerability CVSS: 9.0 15 Jan 2024, 04:15 UTC

A vulnerability, which was classified as critical, was found in Tenda W9 1.0.0.7(4456). This affects the function setWrlBasicInfo of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250707. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0536 tenda vulnerability CVSS: 9.0 15 Jan 2024, 04:15 UTC

A vulnerability, which was classified as critical, has been found in Tenda W9 1.0.0.7(4456). Affected by this issue is the function setWrlAccessList of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250706 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0534 tenda vulnerability CVSS: 8.3 15 Jan 2024, 03:15 UTC

A vulnerability classified as critical has been found in Tenda A15 15.13.07.13. Affected is an unknown function of the file /goform/SetOnlineDevName of the component Web-based Management Interface. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250704. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0533 tenda vulnerability CVSS: 8.3 15 Jan 2024, 03:15 UTC

A vulnerability was found in Tenda A15 15.13.07.13. It has been rated as critical. This issue affects some unknown processing of the file /goform/SetOnlineDevName of the component Web-based Management Interface. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250703. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0532 tenda vulnerability CVSS: 8.3 15 Jan 2024, 02:15 UTC

A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as critical. This vulnerability affects the function set_repeat5 of the file /goform/WifiExtraSet of the component Web-based Management Interface. The manipulation of the argument wpapsk_crypto2_4g/wpapsk_crypto5g leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0531 tenda vulnerability CVSS: 8.3 15 Jan 2024, 02:15 UTC

A vulnerability was found in Tenda A15 15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/setBlackRule of the component Web-based Management Interface. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250701 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-51970 tenda vulnerability CVSS: 0 10 Jan 2024, 16:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

CVE-2023-51969 tenda vulnerability CVSS: 0 10 Jan 2024, 16:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.

CVE-2023-51968 tenda vulnerability CVSS: 0 10 Jan 2024, 16:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.

CVE-2023-51967 tenda vulnerability CVSS: 0 10 Jan 2024, 16:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.

CVE-2023-51962 tenda vulnerability CVSS: 0 10 Jan 2024, 16:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.

CVE-2023-51965 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.

CVE-2023-51964 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.

CVE-2023-51963 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.

CVE-2023-51960 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.

CVE-2023-51959 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

CVE-2023-51958 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.

CVE-2023-51957 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

CVE-2023-51956 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv

CVE-2023-51955 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

CVE-2023-51954 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.

CVE-2023-51953 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

CVE-2023-51952 tenda vulnerability CVSS: 0 10 Jan 2024, 15:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

CVE-2023-51966 tenda vulnerability CVSS: 0 10 Jan 2024, 14:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.

CVE-2023-51961 tenda vulnerability CVSS: 0 10 Jan 2024, 14:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.

CVE-2023-51972 tenda vulnerability CVSS: 0 10 Jan 2024, 13:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.

CVE-2023-51971 tenda vulnerability CVSS: 0 10 Jan 2024, 13:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.

CVE-2023-49427 tenda vulnerability CVSS: 0 10 Jan 2024, 09:15 UTC

Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.

CVE-2023-50585 tenda vulnerability CVSS: 0 09 Jan 2024, 09:15 UTC

Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

CVE-2023-50991 tenda vulnerability CVSS: 0 05 Jan 2024, 10:15 UTC

Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.

CVE-2023-51812 tenda vulnerability CVSS: 0 04 Jan 2024, 19:15 UTC

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.

CVE-2023-51102 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet.

CVE-2023-51101 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo.

CVE-2023-51100 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .

CVE-2023-51099 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .

CVE-2023-51098 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo .

CVE-2023-51097 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetAutoPing.

CVE-2023-51094 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.

CVE-2023-51093 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.

CVE-2023-51092 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.

CVE-2023-51091 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.

CVE-2023-51090 tenda vulnerability CVSS: 0 26 Dec 2023, 18:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.

CVE-2023-51095 tenda vulnerability CVSS: 0 26 Dec 2023, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.

CVE-2023-50992 tenda vulnerability CVSS: 0 20 Dec 2023, 22:15 UTC

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.

CVE-2023-50990 tenda vulnerability CVSS: 0 20 Dec 2023, 22:15 UTC

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.

CVE-2023-50989 tenda vulnerability CVSS: 0 20 Dec 2023, 22:15 UTC

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.

CVE-2023-50988 tenda vulnerability CVSS: 0 20 Dec 2023, 22:15 UTC

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.

CVE-2023-50987 tenda vulnerability CVSS: 0 20 Dec 2023, 22:15 UTC

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.

CVE-2023-50986 tenda vulnerability CVSS: 0 20 Dec 2023, 22:15 UTC

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.

CVE-2023-50985 tenda vulnerability CVSS: 0 20 Dec 2023, 22:15 UTC

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.

CVE-2023-50984 tenda vulnerability CVSS: 0 20 Dec 2023, 22:15 UTC

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.

CVE-2023-50983 tenda vulnerability CVSS: 0 20 Dec 2023, 22:15 UTC

Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.

CVE-2023-49411 tenda vulnerability CVSS: 0 07 Dec 2023, 18:15 UTC

Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.

CVE-2023-49409 tenda vulnerability CVSS: 0 07 Dec 2023, 18:15 UTC

Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.

CVE-2023-49408 tenda vulnerability CVSS: 0 07 Dec 2023, 18:15 UTC

Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.

CVE-2023-49406 tenda vulnerability CVSS: 0 07 Dec 2023, 18:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.

CVE-2023-49405 tenda vulnerability CVSS: 0 07 Dec 2023, 18:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.

CVE-2023-49404 tenda vulnerability CVSS: 0 07 Dec 2023, 18:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.

CVE-2023-50002 tenda vulnerability CVSS: 0 07 Dec 2023, 17:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.

CVE-2023-50001 tenda vulnerability CVSS: 0 07 Dec 2023, 17:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.

CVE-2023-50000 tenda vulnerability CVSS: 0 07 Dec 2023, 17:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.

CVE-2023-49999 tenda vulnerability CVSS: 0 07 Dec 2023, 17:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.

CVE-2023-49410 tenda vulnerability CVSS: 0 07 Dec 2023, 17:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.

CVE-2023-49403 tenda vulnerability CVSS: 0 07 Dec 2023, 17:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.

CVE-2023-49402 tenda vulnerability CVSS: 0 07 Dec 2023, 17:15 UTC

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.

CVE-2023-49436 tenda vulnerability CVSS: 0 07 Dec 2023, 16:15 UTC

Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

CVE-2023-49435 tenda vulnerability CVSS: 0 07 Dec 2023, 16:15 UTC

Tenda AX9 V22.03.01.46 is vulnerable to command injection.

CVE-2023-49434 tenda vulnerability CVSS: 0 07 Dec 2023, 16:15 UTC

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.

CVE-2023-49433 tenda vulnerability CVSS: 0 07 Dec 2023, 16:15 UTC

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.

CVE-2023-49432 tenda vulnerability CVSS: 0 07 Dec 2023, 16:15 UTC

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.

CVE-2023-49431 tenda vulnerability CVSS: 0 07 Dec 2023, 16:15 UTC

Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

CVE-2023-49430 tenda vulnerability CVSS: 0 07 Dec 2023, 16:15 UTC

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.

CVE-2023-49429 tenda vulnerability CVSS: 0 07 Dec 2023, 16:15 UTC

Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.

CVE-2023-49437 tenda vulnerability CVSS: 0 07 Dec 2023, 15:15 UTC

Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

CVE-2023-49428 tenda vulnerability CVSS: 0 07 Dec 2023, 15:15 UTC

Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

CVE-2023-49426 tenda vulnerability CVSS: 0 07 Dec 2023, 15:15 UTC

Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

CVE-2023-49425 tenda vulnerability CVSS: 0 07 Dec 2023, 15:15 UTC

Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .

CVE-2023-49424 tenda vulnerability CVSS: 0 07 Dec 2023, 14:15 UTC

Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

CVE-2023-48964 tenda vulnerability CVSS: 0 30 Nov 2023, 14:15 UTC

Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/WifiMacFilterSet.

CVE-2023-48963 tenda vulnerability CVSS: 0 30 Nov 2023, 14:15 UTC

Tenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/wifiSSIDget.

CVE-2023-45484 tenda vulnerability CVSS: 0 29 Nov 2023, 06:15 UTC

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGuestBasic.

CVE-2023-45483 tenda vulnerability CVSS: 0 29 Nov 2023, 06:15 UTC

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcontrol_time.

CVE-2023-45482 tenda vulnerability CVSS: 0 29 Nov 2023, 06:15 UTC

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.

CVE-2023-45481 tenda vulnerability CVSS: 0 29 Nov 2023, 06:15 UTC

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg.

CVE-2023-45480 tenda vulnerability CVSS: 0 29 Nov 2023, 06:15 UTC

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the function sub_47D878.

CVE-2023-45479 tenda vulnerability CVSS: 0 29 Nov 2023, 06:15 UTC

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in the function sub_49E098.

CVE-2023-49044 tenda vulnerability CVSS: 0 27 Nov 2023, 21:15 UTC

Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set.

CVE-2023-49047 tenda vulnerability CVSS: 0 27 Nov 2023, 17:15 UTC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.

CVE-2023-49042 tenda vulnerability CVSS: 0 27 Nov 2023, 17:15 UTC

Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi.

CVE-2023-49040 tenda vulnerability CVSS: 0 27 Nov 2023, 17:15 UTC

An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function.

CVE-2023-49046 tenda vulnerability CVSS: 0 27 Nov 2023, 16:15 UTC

Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule.

CVE-2023-49043 tenda vulnerability CVSS: 0 27 Nov 2023, 16:15 UTC

Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat.

CVE-2023-48111 tenda vulnerability CVSS: 0 20 Nov 2023, 20:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

CVE-2023-48110 tenda vulnerability CVSS: 0 20 Nov 2023, 20:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

CVE-2023-48109 tenda vulnerability CVSS: 0 20 Nov 2023, 20:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

CVE-2023-38823 tenda vulnerability CVSS: 0 20 Nov 2023, 20:15 UTC

Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.

CVE-2022-45781 tenda vulnerability CVSS: 0 14 Nov 2023, 22:15 UTC

Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /goform/SetOnlineDevName.

CVE-2023-47456 tenda vulnerability CVSS: 0 07 Nov 2023, 15:15 UTC

Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat.

CVE-2023-47455 tenda vulnerability CVSS: 0 07 Nov 2023, 15:15 UTC

Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.

CVE-2023-43886 tenda vulnerability CVSS: 0 07 Nov 2023, 08:15 UTC

A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to overwrite memory.

CVE-2023-43885 tenda vulnerability CVSS: 0 07 Nov 2023, 08:15 UTC

Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.

CVE-2023-46370 tenda vulnerability CVSS: 0 25 Oct 2023, 18:17 UTC

Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.

CVE-2023-46369 tenda vulnerability CVSS: 0 25 Oct 2023, 18:17 UTC

Tenda W18E V16.01.0.8(1576) contains a stack overflow vulnerability via the portMirrorMirroredPorts parameter in the formSetNetCheckTools function.

CVE-2023-40830 tenda vulnerability CVSS: 0 03 Oct 2023, 20:15 UTC

Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.

CVE-2023-42320 tenda vulnerability CVSS: 0 18 Sep 2023, 16:15 UTC

Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.

CVE-2023-4498 tenda vulnerability CVSS: 0 06 Sep 2023, 17:15 UTC

Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn should be accessible to authenticated users only

CVE-2021-40546 tenda vulnerability CVSS: 0 05 Sep 2023, 19:15 UTC

Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi.

CVE-2023-4744 tenda vulnerability CVSS: 10.0 04 Sep 2023, 00:15 UTC

A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238633 was assigned to this vulnerability.

CVE-2023-40848 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "sub_7D858."

CVE-2023-40847 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "initIpAddrInfo." In the function, it reads in a user-provided parameter, and the variable is passed to the function without any length check.

CVE-2023-40845 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'sub_34FD0.' In the function, it reads user provided parameters and passes variables to the function without any length checks.

CVE-2023-40844 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'formWifiBasicSet.'

CVE-2023-40843 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "sub_73004."

CVE-2023-40842 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tengda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "R7WebsSecurityHandler."

CVE-2023-40841 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "add_white_node,"

CVE-2023-40840 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "fromGetWirelessRepeat."

CVE-2023-40839 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADF3C' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADF3C" function to execute commands.

CVE-2023-40838 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_3A1D0' contains a command execution vulnerability.

CVE-2023-40837 tenda vulnerability CVSS: 0 30 Aug 2023, 17:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADD50' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADD50" function to execute commands.

CVE-2023-41563 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.

CVE-2023-41562 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet.

CVE-2023-41561 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.

CVE-2023-41560 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter firewallEn at url /goform/SetFirewallCfg.

CVE-2023-41559 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.

CVE-2023-41558 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter timeZone at url /goform/SetSysTimeCfg.

CVE-2023-41557 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.

CVE-2023-41556 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetIpMacBind.

CVE-2023-41555 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.

CVE-2023-41554 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter wpapsk_crypto at url /goform/WifiExtraSet.

CVE-2023-41553 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetStaticRouteCfg.

CVE-2023-41552 tenda vulnerability CVSS: 0 30 Aug 2023, 13:15 UTC

Tenda AC7 V1.0 V15.03.06.44 and Tenda AC9 V3.0 V15.03.06.42_multi were discovered to contain a stack overflow via parameter ssid at url /goform/fast_setting_wifi_set.

CVE-2023-40846 tenda vulnerability CVSS: 0 28 Aug 2023, 14:15 UTC

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function sub_90998.

CVE-2023-40798 tenda vulnerability CVSS: 0 25 Aug 2023, 16:15 UTC

In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.

CVE-2023-40797 tenda vulnerability CVSS: 0 25 Aug 2023, 16:15 UTC

In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.

CVE-2023-40915 tenda vulnerability CVSS: 0 25 Aug 2023, 15:15 UTC

Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.

CVE-2023-40802 tenda vulnerability CVSS: 0 25 Aug 2023, 15:15 UTC

The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn

CVE-2023-40801 tenda vulnerability CVSS: 0 25 Aug 2023, 15:15 UTC

The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn

CVE-2023-40800 tenda vulnerability CVSS: 0 25 Aug 2023, 15:15 UTC

The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn.

CVE-2023-40799 tenda vulnerability CVSS: 0 25 Aug 2023, 15:15 UTC

Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.

CVE-2023-40904 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

CVE-2023-40902 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.

CVE-2023-40901 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at url /goform/setMacFilterCfg.

CVE-2023-40900 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

CVE-2023-40899 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

CVE-2023-40898 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/SetSysTimeCfg.

CVE-2023-40897 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter mac at /goform/GetParentControlInfo.

CVE-2023-40896 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.

CVE-2023-40895 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.

CVE-2023-40894 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetStaticRouteCfg.

CVE-2023-40893 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

CVE-2023-40892 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and schedEndTime at /goform/openSchedWifi.

CVE-2023-40891 tenda vulnerability CVSS: 0 24 Aug 2023, 18:15 UTC

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform/SetFirewallCfg.

CVE-2023-39786 tenda vulnerability CVSS: 0 21 Aug 2023, 01:15 UTC

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function.

CVE-2023-39785 tenda vulnerability CVSS: 0 21 Aug 2023, 01:15 UTC

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function.

CVE-2023-39784 tenda vulnerability CVSS: 0 21 Aug 2023, 01:15 UTC

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function.

CVE-2023-39673 tenda vulnerability CVSS: 0 18 Aug 2023, 03:15 UTC

Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().

CVE-2023-39672 tenda vulnerability CVSS: 0 18 Aug 2023, 03:15 UTC

Tenda WH450 v1.0.0.18 was discovered to contain a buffer overflow via the function fgets.

CVE-2023-39670 tenda vulnerability CVSS: 0 18 Aug 2023, 03:15 UTC

Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets.

CVE-2023-39829 tenda vulnerability CVSS: 0 14 Aug 2023, 21:15 UTC

Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.

CVE-2023-39828 tenda vulnerability CVSS: 0 14 Aug 2023, 21:15 UTC

Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.

CVE-2023-39827 tenda vulnerability CVSS: 0 14 Aug 2023, 21:15 UTC

Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.

CVE-2023-38940 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVE-2023-38939 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda F1202 V1.2.0.9 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the mit_ssid parameter in the formWrlsafeset function.

CVE-2023-38938 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter at /L7Im.

CVE-2023-38937 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.

CVE-2023-38936 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

CVE-2023-38935 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.

CVE-2023-38934 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.

CVE-2023-38933 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.

CVE-2023-38932 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter in the SafeEmailFilter function.

CVE-2023-38931 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.

CVE-2023-38930 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

CVE-2023-38929 tenda vulnerability CVSS: 0 07 Aug 2023, 19:15 UTC

Tenda 4G300 v1.01.42 was discovered to contain a stack overflow via the page parameter at /VirtualSer.

CVE-2023-37723 tenda vulnerability CVSS: 0 14 Jul 2023, 00:15 UTC

Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromqossetting.

CVE-2023-37722 tenda vulnerability CVSS: 0 14 Jul 2023, 00:15 UTC

Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeUrlFilter.

CVE-2023-37721 tenda vulnerability CVSS: 0 14 Jul 2023, 00:15 UTC

Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeMacFilter.

CVE-2023-37719 tenda vulnerability CVSS: 0 14 Jul 2023, 00:15 UTC

Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromP2pListFilter.

CVE-2023-37718 tenda vulnerability CVSS: 0 14 Jul 2023, 00:15 UTC

Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeClientFilter.

CVE-2023-37717 tenda vulnerability CVSS: 0 14 Jul 2023, 00:15 UTC

Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient.

CVE-2023-37716 tenda vulnerability CVSS: 0 14 Jul 2023, 00:15 UTC

Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting.

CVE-2023-37715 tenda vulnerability CVSS: 0 14 Jul 2023, 00:15 UTC

Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function frmL7ProtForm.

CVE-2023-37714 tenda vulnerability CVSS: 0 14 Jul 2023, 00:15 UTC

Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromRouteStatic.

CVE-2023-37712 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.

CVE-2023-37711 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.

CVE-2023-37710 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

CVE-2023-37707 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.

CVE-2023-37706 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.

CVE-2023-37705 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.

CVE-2023-37704 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.

CVE-2023-37703 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

CVE-2023-37702 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.

CVE-2023-37701 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

CVE-2023-37700 tenda vulnerability CVSS: 0 10 Jul 2023, 17:15 UTC

Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVE-2022-40010 tenda vulnerability CVSS: 0 26 Jun 2023, 17:15 UTC

Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vulnerability via the deviceId parameter in the Parental Control module.

CVE-2023-34571 tenda vulnerability CVSS: 0 08 Jun 2023, 15:15 UTC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet.

CVE-2023-34570 tenda vulnerability CVSS: 0 08 Jun 2023, 15:15 UTC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.

CVE-2023-34569 tenda vulnerability CVSS: 0 08 Jun 2023, 15:15 UTC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

CVE-2023-34568 tenda vulnerability CVSS: 0 08 Jun 2023, 15:15 UTC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

CVE-2023-34567 tenda vulnerability CVSS: 0 08 Jun 2023, 15:15 UTC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.

CVE-2023-34566 tenda vulnerability CVSS: 0 08 Jun 2023, 15:15 UTC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.

CVE-2023-33530 tenda vulnerability CVSS: 0 06 Jun 2023, 13:15 UTC

There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.

CVE-2023-33675 tenda vulnerability CVSS: 0 02 Jun 2023, 20:15 UTC

Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_list_Info function.

CVE-2023-33673 tenda vulnerability CVSS: 0 02 Jun 2023, 20:15 UTC

Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

CVE-2023-33672 tenda vulnerability CVSS: 0 02 Jun 2023, 20:15 UTC

Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.

CVE-2023-33671 tenda vulnerability CVSS: 0 02 Jun 2023, 20:15 UTC

Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.

CVE-2023-33670 tenda vulnerability CVSS: 0 02 Jun 2023, 20:15 UTC

Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function.

CVE-2023-33669 tenda vulnerability CVSS: 0 02 Jun 2023, 20:15 UTC

Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function.

CVE-2023-2923 tenda vulnerability CVSS: 6.5 27 May 2023, 08:15 UTC

A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability is the function fromDhcpListClient. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-230077 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-31587 tenda vulnerability CVSS: 0 16 May 2023, 15:15 UTC

Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.

CVE-2023-2649 tenda vulnerability CVSS: 8.3 11 May 2023, 08:15 UTC

A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/ate of the component Service Port 7329. The manipulation of the argument v2 leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-228778 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-30356 tenda vulnerability CVSS: 0 10 May 2023, 16:15 UTC

Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers to update the device with crafted firmware

CVE-2023-30354 tenda vulnerability CVSS: 0 10 May 2023, 16:15 UTC

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.

CVE-2023-30353 tenda vulnerability CVSS: 0 10 May 2023, 16:15 UTC

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.

CVE-2023-30352 tenda vulnerability CVSS: 0 10 May 2023, 16:15 UTC

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.

CVE-2023-30351 tenda vulnerability CVSS: 0 10 May 2023, 16:15 UTC

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.

CVE-2023-30135 tenda vulnerability CVSS: 0 05 May 2023, 02:15 UTC

Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.

CVE-2023-29681 tenda vulnerability CVSS: 0 01 May 2023, 22:15 UTC

Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.

CVE-2023-29680 tenda vulnerability CVSS: 0 01 May 2023, 22:15 UTC

Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.

CVE-2023-30378 tenda vulnerability CVSS: 0 24 Apr 2023, 15:15 UTC

In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.

CVE-2023-30376 tenda vulnerability CVSS: 0 24 Apr 2023, 15:15 UTC

In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.

CVE-2023-30375 tenda vulnerability CVSS: 0 24 Apr 2023, 15:15 UTC

In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.

CVE-2023-30373 tenda vulnerability CVSS: 0 24 Apr 2023, 15:15 UTC

In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.

CVE-2023-30372 tenda vulnerability CVSS: 0 24 Apr 2023, 15:15 UTC

In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.

CVE-2023-30371 tenda vulnerability CVSS: 0 24 Apr 2023, 15:15 UTC

In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.

CVE-2023-30370 tenda vulnerability CVSS: 0 24 Apr 2023, 15:15 UTC

In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.

CVE-2023-30369 tenda vulnerability CVSS: 0 24 Apr 2023, 14:15 UTC

Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.

CVE-2023-30368 tenda vulnerability CVSS: 0 24 Apr 2023, 14:15 UTC

Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.

CVE-2023-27076 tenda vulnerability CVSS: 0 10 Apr 2023, 21:15 UTC

Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.

CVE-2023-27021 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27020 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27019 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27018 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27017 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27016 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27015 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75C0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27014 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC38 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27013 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27012 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25220 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25219 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25218 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25217 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formWifiBasicSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25216 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25215 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25214 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25213 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the check_param_changed function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25212 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetWirelessRepeat function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25211 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25210 tenda vulnerability CVSS: 0 07 Apr 2023, 02:15 UTC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetSysTime function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-26976 tenda vulnerability CVSS: 0 04 Apr 2023, 02:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVE-2023-27042 tenda vulnerability CVSS: 0 24 Mar 2023, 23:15 UTC

Tenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg.

CVE-2023-27079 tenda vulnerability CVSS: 0 23 Mar 2023, 14:15 UTC

Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package

CVE-2023-26806 tenda vulnerability CVSS: 0 19 Mar 2023, 01:15 UTC

Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,

CVE-2023-26805 tenda vulnerability CVSS: 0 19 Mar 2023, 01:15 UTC

Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.

CVE-2023-27240 tenda vulnerability CVSS: 0 15 Mar 2023, 06:15 UTC

Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.

CVE-2023-27239 tenda vulnerability CVSS: 0 15 Mar 2023, 06:15 UTC

Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet.

CVE-2023-27065 tenda vulnerability CVSS: 0 13 Mar 2023, 14:15 UTC

Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2023-27064 tenda vulnerability CVSS: 0 13 Mar 2023, 14:15 UTC

Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2023-27063 tenda vulnerability CVSS: 0 13 Mar 2023, 14:15 UTC

Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2023-27062 tenda vulnerability CVSS: 0 13 Mar 2023, 14:15 UTC

Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2023-27061 tenda vulnerability CVSS: 0 13 Mar 2023, 14:15 UTC

Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2023-25235 tenda vulnerability CVSS: 0 27 Feb 2023, 16:15 UTC

Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid.

CVE-2023-25234 tenda vulnerability CVSS: 0 27 Feb 2023, 16:15 UTC

Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.

CVE-2023-25233 tenda vulnerability CVSS: 0 27 Feb 2023, 16:15 UTC

Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.

CVE-2023-25231 tenda vulnerability CVSS: 0 27 Feb 2023, 16:15 UTC

Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.

CVE-2023-23080 tenda vulnerability CVSS: 0 27 Feb 2023, 14:15 UTC

Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS Tenda IT7-PRS<=V2209020908.

CVE-2023-24212 tenda vulnerability CVSS: 0 23 Feb 2023, 23:15 UTC

Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.

CVE-2023-0782 tenda vulnerability CVSS: 8.3 11 Feb 2023, 18:15 UTC

A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220640.

CVE-2022-48130 tenda vulnerability CVSS: 0 02 Feb 2023, 21:22 UTC

Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN.

CVE-2023-24170 tenda vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.

CVE-2023-24169 tenda vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.

CVE-2023-24167 tenda vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node.

CVE-2023-24166 tenda vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.

CVE-2023-24165 tenda vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo.

CVE-2023-24164 tenda vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318.

CVE-2022-45995 tenda vulnerability CVSS: 0 05 Jan 2023, 14:15 UTC

There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not to restart or even execute arbitrary code. It is a different vulnerability from CVE-2022-2414.

CVE-2022-47128 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet.

CVE-2022-47127 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd parameter at /goform/WifiBasicSet.

CVE-2022-47126 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.

CVE-2022-47125 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet.

CVE-2022-47124 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet.

CVE-2022-47123 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet.

CVE-2022-47122 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd_5g parameter at /goform/WifiBasicSet.

CVE-2022-47121 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

CVE-2022-47120 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

CVE-2022-47119 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet.

CVE-2022-47118 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.

CVE-2022-47117 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet.

CVE-2022-47116 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the SYSPS parameter at /goform/SysToolChangePwd.

CVE-2022-47115 tenda vulnerability CVSS: 0 30 Dec 2022, 21:15 UTC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicSet.

CVE-2022-46551 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the time parameter at /goform/saveParentControlInfo.

CVE-2022-46550 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the urls parameter at /goform/saveParentControlInfo.

CVE-2022-46549 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/saveParentControlInfo.

CVE-2022-46548 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/DhcpListClient.

CVE-2022-46547 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/VirtualSer.

CVE-2022-46546 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the entrys parameter at /goform/RouteStatic.

CVE-2022-46545 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.

CVE-2022-46544 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the cmdinput parameter at /goform/exeCommand.

CVE-2022-46543 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mitInterface parameter at /goform/addressNat.

CVE-2022-46542 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the page parameter at /goform/addressNat.

CVE-2022-46541 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the ssid parameter at /goform/fast_setting_wifi_set.

CVE-2022-46540 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the entrys parameter at /goform/addressNat.

CVE-2022-46539 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the security_5g parameter at /goform/WifiBasicSet.

CVE-2022-46538 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.

CVE-2022-46537 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the security parameter at /goform/WifiBasicSet.

CVE-2022-46536 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeedUp parameter at /goform/SetClientState.

CVE-2022-46535 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/SetClientState.

CVE-2022-46534 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the speed_dir parameter at /goform/SetSpeedWan.

CVE-2022-46533 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the limitSpeed parameter at /goform/SetClientState.

CVE-2022-46532 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceMac parameter at /goform/addWifiMacFilter.

CVE-2022-46531 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the deviceId parameter at /goform/addWifiMacFilter.

CVE-2022-46530 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo.

CVE-2022-45666 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.

CVE-2022-45665 tenda vulnerability CVSS: 0 20 Dec 2022, 15:15 UTC

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

CVE-2022-46109 tenda vulnerability CVSS: 0 16 Dec 2022, 17:15 UTC

Tenda AC15 V15.03.06.23 is vulnerable to Buffer Overflow via function formSetClientState.

CVE-2022-45997 tenda vulnerability CVSS: 0 12 Dec 2022, 16:15 UTC

Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.

CVE-2022-45996 tenda vulnerability CVSS: 0 12 Dec 2022, 16:15 UTC

Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.

CVE-2022-45980 tenda vulnerability CVSS: 0 12 Dec 2022, 15:15 UTC

Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .

CVE-2022-45979 tenda vulnerability CVSS: 0 12 Dec 2022, 15:15 UTC

Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .

CVE-2022-45977 tenda vulnerability CVSS: 0 12 Dec 2022, 15:15 UTC

Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.

CVE-2022-45043 tenda vulnerability CVSS: 0 12 Dec 2022, 15:15 UTC

Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.

CVE-2022-45525 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.

CVE-2022-45524 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.

CVE-2022-45523 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.

CVE-2022-45522 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.

CVE-2022-45521 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.

CVE-2022-45520 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.

CVE-2022-45519 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.

CVE-2022-45518 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind.

CVE-2022-45517 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer.

CVE-2022-45516 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting.

CVE-2022-45515 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat.

CVE-2022-45514 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/webExcptypemanFilter.

CVE-2022-45513 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter.

CVE-2022-45512 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.

CVE-2022-45511 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.

CVE-2022-45510 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.

CVE-2022-45509 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.

CVE-2022-45508 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.

CVE-2022-45507 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.

CVE-2022-45506 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.

CVE-2022-45505 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.

CVE-2022-45504 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.

CVE-2022-45503 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the linkEn parameter at /goform/setAutoPing.

CVE-2022-45501 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.

CVE-2022-45499 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.

CVE-2022-45498 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.

CVE-2022-45497 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.

CVE-2022-44932 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service.

CVE-2022-44931 tenda vulnerability CVSS: 0 08 Dec 2022, 16:15 UTC

Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

CVE-2022-45672 tenda vulnerability CVSS: 0 02 Dec 2022, 18:15 UTC

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function.

CVE-2022-45671 tenda vulnerability CVSS: 0 02 Dec 2022, 18:15 UTC

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRule function.

CVE-2022-45670 tenda vulnerability CVSS: 0 02 Dec 2022, 18:15 UTC

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.

CVE-2022-45669 tenda vulnerability CVSS: 0 02 Dec 2022, 18:15 UTC

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet function.

CVE-2022-45668 tenda vulnerability CVSS: 0 02 Dec 2022, 18:15 UTC

Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

CVE-2022-45667 tenda vulnerability CVSS: 0 02 Dec 2022, 18:15 UTC

Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

CVE-2022-45664 tenda vulnerability CVSS: 0 02 Dec 2022, 18:15 UTC

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDget function.

CVE-2022-45663 tenda vulnerability CVSS: 0 02 Dec 2022, 18:15 UTC

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.

CVE-2022-45641 tenda vulnerability CVSS: 0 02 Dec 2022, 18:15 UTC

Tenda AC6V1.0 V15.03.05.19 is vulnerable to Buffer Overflow via formSetMacFilterCfg.

CVE-2022-45674 tenda vulnerability CVSS: 0 02 Dec 2022, 17:15 UTC

Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

CVE-2022-45673 tenda vulnerability CVSS: 0 02 Dec 2022, 17:15 UTC

Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

CVE-2022-44367 tenda vulnerability CVSS: 0 02 Dec 2022, 17:15 UTC

Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.

CVE-2022-44366 tenda vulnerability CVSS: 0 02 Dec 2022, 17:15 UTC

Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo.

CVE-2022-44365 tenda vulnerability CVSS: 0 02 Dec 2022, 17:15 UTC

Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.

CVE-2022-44363 tenda vulnerability CVSS: 0 02 Dec 2022, 17:15 UTC

Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.

CVE-2022-44362 tenda vulnerability CVSS: 0 02 Dec 2022, 17:15 UTC

Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.

CVE-2022-45640 tenda vulnerability CVSS: 0 01 Dec 2022, 05:15 UTC

Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).

CVE-2022-45337 tenda vulnerability CVSS: 0 30 Nov 2022, 03:15 UTC

Tenda TX9 Pro v22.03.02.10 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.

CVE-2022-44183 tenda vulnerability CVSS: 0 21 Nov 2022, 18:15 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.

CVE-2022-44180 tenda vulnerability CVSS: 0 21 Nov 2022, 18:15 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.

CVE-2022-44178 tenda vulnerability CVSS: 0 21 Nov 2022, 18:15 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.

CVE-2022-44177 tenda vulnerability CVSS: 0 21 Nov 2022, 18:15 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.

CVE-2022-44176 tenda vulnerability CVSS: 0 21 Nov 2022, 18:15 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.

CVE-2022-44175 tenda vulnerability CVSS: 0 21 Nov 2022, 18:15 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.

CVE-2022-44174 tenda vulnerability CVSS: 0 21 Nov 2022, 18:15 UTC

Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.

CVE-2022-44172 tenda vulnerability CVSS: 0 21 Nov 2022, 18:15 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.

CVE-2022-44171 tenda vulnerability CVSS: 0 21 Nov 2022, 18:15 UTC

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.

CVE-2022-44163 tenda vulnerability CVSS: 0 21 Nov 2022, 16:15 UTC

Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.

CVE-2022-44158 tenda vulnerability CVSS: 0 21 Nov 2022, 16:15 UTC

Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name.

CVE-2022-44156 tenda vulnerability CVSS: 0 21 Nov 2022, 16:15 UTC

Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.

CVE-2022-44169 tenda vulnerability CVSS: 0 21 Nov 2022, 15:15 UTC

Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function formSetVirtualSer.

CVE-2022-44168 tenda vulnerability CVSS: 0 21 Nov 2022, 15:15 UTC

Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function fromSetRouteStatic..

CVE-2022-44167 tenda vulnerability CVSS: 0 21 Nov 2022, 15:15 UTC

Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.

CVE-2022-42060 tenda vulnerability CVSS: 0 15 Nov 2022, 03:15 UTC

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2022-42058 tenda vulnerability CVSS: 0 15 Nov 2022, 03:15 UTC

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2022-42053 tenda vulnerability CVSS: 0 15 Nov 2022, 03:15 UTC

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.

CVE-2022-41396 tenda vulnerability CVSS: 0 15 Nov 2022, 03:15 UTC

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.

CVE-2022-41395 tenda vulnerability CVSS: 0 15 Nov 2022, 03:15 UTC

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.

CVE-2022-40846 tenda vulnerability CVSS: 0 15 Nov 2022, 03:15 UTC

In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.

CVE-2022-40844 tenda vulnerability CVSS: 0 15 Nov 2022, 03:15 UTC

In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL body.

CVE-2022-40847 tenda vulnerability CVSS: 0 15 Nov 2022, 02:15 UTC

In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerability allows attackers to run arbitrary commands on the server via the hostname parameter.

CVE-2022-40845 tenda vulnerability CVSS: 0 15 Nov 2022, 02:15 UTC

The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information which they're not explicitly authorized to have.

CVE-2022-40843 tenda vulnerability CVSS: 0 15 Nov 2022, 02:15 UTC

The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. This leads to authenticated attackers having the ability to read the routers syslog.log file which contains the MD5 password of the Administrator's user account.

CVE-2022-43108 tenda vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

CVE-2022-43107 tenda vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

CVE-2022-43106 tenda vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.

CVE-2022-43105 tenda vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.

CVE-2022-43104 tenda vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

CVE-2022-43103 tenda vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.

CVE-2022-43102 tenda vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.

CVE-2022-43101 tenda vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

CVE-2022-40876 tenda vulnerability CVSS: 0 27 Oct 2022, 21:15 UTC

In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).

CVE-2022-40875 tenda vulnerability CVSS: 0 27 Oct 2022, 18:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.

CVE-2022-40874 tenda vulnerability CVSS: 0 27 Oct 2022, 18:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.

CVE-2022-42233 tenda vulnerability CVSS: 0 20 Oct 2022, 17:15 UTC

Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.

CVE-2022-43029 tenda vulnerability CVSS: 0 19 Oct 2022, 19:15 UTC

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the time parameter at /goform/SetSysTimeCfg.

CVE-2022-43028 tenda vulnerability CVSS: 0 19 Oct 2022, 19:15 UTC

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCfg.

CVE-2022-43027 tenda vulnerability CVSS: 0 19 Oct 2022, 19:15 UTC

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewallCfg.

CVE-2022-43026 tenda vulnerability CVSS: 0 19 Oct 2022, 19:15 UTC

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.

CVE-2022-43025 tenda vulnerability CVSS: 0 19 Oct 2022, 19:15 UTC

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.

CVE-2022-43024 tenda vulnerability CVSS: 0 19 Oct 2022, 19:15 UTC

Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

CVE-2022-43260 tenda vulnerability CVSS: 0 18 Oct 2022, 15:15 UTC

Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.

CVE-2022-43259 tenda vulnerability CVSS: 0 18 Oct 2022, 15:15 UTC

Tenda AC15 V15.03.05.18 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function.

CVE-2022-42171 tenda vulnerability CVSS: 0 17 Oct 2022, 14:15 UTC

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.

CVE-2022-42170 tenda vulnerability CVSS: 0 17 Oct 2022, 14:15 UTC

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.

CVE-2022-42169 tenda vulnerability CVSS: 0 17 Oct 2022, 14:15 UTC

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter.

CVE-2022-42168 tenda vulnerability CVSS: 0 17 Oct 2022, 14:15 UTC

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind.

CVE-2022-42167 tenda vulnerability CVSS: 0 17 Oct 2022, 14:15 UTC

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.

CVE-2022-42166 tenda vulnerability CVSS: 0 17 Oct 2022, 14:15 UTC

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.

CVE-2022-42165 tenda vulnerability CVSS: 0 17 Oct 2022, 13:15 UTC

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.

CVE-2022-42164 tenda vulnerability CVSS: 0 17 Oct 2022, 13:15 UTC

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState.

CVE-2022-42163 tenda vulnerability CVSS: 0 17 Oct 2022, 13:15 UTC

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.

CVE-2022-41485 tenda vulnerability CVSS: 0 13 Oct 2022, 19:15 UTC

Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47ce00 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2022-41484 tenda vulnerability CVSS: 0 13 Oct 2022, 19:15 UTC

Tenda AC1900 AP500(US)_V1_180320(Beta) was discovered to contain a buffer overflow in the 0x32384 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2022-41483 tenda vulnerability CVSS: 0 13 Oct 2022, 19:15 UTC

Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x4a12cc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2022-41482 tenda vulnerability CVSS: 0 13 Oct 2022, 19:15 UTC

Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47c5dc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2022-41481 tenda vulnerability CVSS: 0 13 Oct 2022, 19:15 UTC

Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47de1c function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2022-41480 tenda vulnerability CVSS: 0 13 Oct 2022, 19:15 UTC

Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x475dc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

CVE-2022-42087 tenda vulnerability CVSS: 0 12 Oct 2022, 19:15 UTC

Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

CVE-2022-42086 tenda vulnerability CVSS: 0 12 Oct 2022, 19:15 UTC

Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.

CVE-2022-42081 tenda vulnerability CVSS: 0 12 Oct 2022, 19:15 UTC

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via sched_end_time parameter.

CVE-2022-42080 tenda vulnerability CVSS: 0 12 Oct 2022, 19:15 UTC

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a heap overflow via sched_start_time parameter.

CVE-2022-42079 tenda vulnerability CVSS: 0 12 Oct 2022, 19:15 UTC

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.

CVE-2022-42078 tenda vulnerability CVSS: 0 12 Oct 2022, 19:15 UTC

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

CVE-2022-42077 tenda vulnerability CVSS: 0 12 Oct 2022, 19:15 UTC

Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

CVE-2022-40942 tenda vulnerability CVSS: 0 28 Sep 2022, 15:15 UTC

Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.

CVE-2022-40107 tenda vulnerability CVSS: 0 23 Sep 2022, 19:15 UTC

Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formexeCommand function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVE-2022-40106 tenda vulnerability CVSS: 0 23 Sep 2022, 19:15 UTC

Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the set_local_time function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVE-2022-40105 tenda vulnerability CVSS: 0 23 Sep 2022, 19:15 UTC

Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formWifiMacFilterGet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVE-2022-40104 tenda vulnerability CVSS: 0 23 Sep 2022, 19:15 UTC

Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formwrlSSIDget function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVE-2022-40103 tenda vulnerability CVSS: 0 23 Sep 2022, 19:15 UTC

Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVE-2022-40102 tenda vulnerability CVSS: 0 23 Sep 2022, 19:15 UTC

Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formwrlSSIDset function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVE-2022-40101 tenda vulnerability CVSS: 0 23 Sep 2022, 19:15 UTC

Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formWifiMacFilterSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVE-2022-40100 tenda vulnerability CVSS: 0 23 Sep 2022, 19:15 UTC

Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.

CVE-2022-40868 tenda vulnerability CVSS: 0 23 Sep 2022, 15:15 UTC

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/

CVE-2022-40867 tenda vulnerability CVSS: 0 23 Sep 2022, 15:15 UTC

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/

CVE-2022-40866 tenda vulnerability CVSS: 0 23 Sep 2022, 15:15 UTC

Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/

CVE-2022-40861 tenda vulnerability CVSS: 0 23 Sep 2022, 15:15 UTC

Tenda AC18 router V15.03.05.19 contains a stack overflow vulnerability in the formSetQosBand->FUN_0007db78 function with the request /goform/SetNetControlList/

CVE-2022-40855 tenda vulnerability CVSS: 0 23 Sep 2022, 15:15 UTC

Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code Execution (RCE) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.

CVE-2022-40854 tenda vulnerability CVSS: 0 23 Sep 2022, 15:15 UTC

Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set

CVE-2022-40851 tenda vulnerability CVSS: 0 23 Sep 2022, 15:15 UTC

Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.

CVE-2022-40076 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetWifiGusetBasic.

CVE-2022-40075 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, form_fast_setting_wifi_set.

CVE-2022-40074 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, setSchedWifi.

CVE-2022-40073 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, saveParentControlInfo.

CVE-2022-40072 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: setSmartPowerManagement.

CVE-2022-40071 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, formSetDeviceName.

CVE-2022-40070 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via bin/httpd, function: formSetFirewallCfg.

CVE-2022-40069 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

]Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: fromSetSysTime.

CVE-2022-40068 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetQosBand.

CVE-2022-40067 tenda vulnerability CVSS: 0 19 Sep 2022, 15:15 UTC

Tenda AC21 V 16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetVirtualSer.

CVE-2022-38831 tenda vulnerability CVSS: 0 16 Sep 2022, 15:15 UTC

Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList

CVE-2022-38830 tenda vulnerability CVSS: 0 16 Sep 2022, 15:15 UTC

Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status.

CVE-2022-38829 tenda vulnerability CVSS: 0 16 Sep 2022, 15:15 UTC

Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg.

CVE-2022-36586 tenda vulnerability CVSS: 0 08 Sep 2022, 00:15 UTC

In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.

CVE-2022-36585 tenda vulnerability CVSS: 0 07 Sep 2022, 23:15 UTC

In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.

CVE-2022-38314 tenda vulnerability CVSS: 0 07 Sep 2022, 19:15 UTC

Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.

CVE-2022-38313 tenda vulnerability CVSS: 0 07 Sep 2022, 19:15 UTC

Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.

CVE-2022-38312 tenda vulnerability CVSS: 0 07 Sep 2022, 19:15 UTC

Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.

CVE-2022-38311 tenda vulnerability CVSS: 0 07 Sep 2022, 19:15 UTC

Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.

CVE-2022-38310 tenda vulnerability CVSS: 0 07 Sep 2022, 19:15 UTC

Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

CVE-2022-38309 tenda vulnerability CVSS: 0 07 Sep 2022, 19:15 UTC

Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

CVE-2022-36587 tenda vulnerability CVSS: 0 07 Sep 2022, 17:15 UTC

In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.

CVE-2022-36584 tenda vulnerability CVSS: 0 06 Sep 2022, 17:15 UTC

In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.

CVE-2022-36571 tenda vulnerability CVSS: 0 31 Aug 2022, 20:15 UTC

Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.

CVE-2022-36570 tenda vulnerability CVSS: 0 31 Aug 2022, 20:15 UTC

Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.

CVE-2022-36569 tenda vulnerability CVSS: 0 31 Aug 2022, 20:15 UTC

Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg.

CVE-2022-36568 tenda vulnerability CVSS: 0 31 Aug 2022, 20:15 UTC

Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList.

CVE-2022-38510 tenda vulnerability CVSS: 0 29 Aug 2022, 00:15 UTC

Tenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList.

CVE-2022-38571 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem.

CVE-2022-38570 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter.

CVE-2022-38569 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.

CVE-2022-38568 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter.

CVE-2022-38567 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter.

CVE-2022-38566 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter.

CVE-2022-38565 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter.

CVE-2022-38564 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter.

CVE-2022-38563 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter.

CVE-2022-38562 tenda vulnerability CVSS: 0 28 Aug 2022, 17:15 UTC

Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter.

CVE-2022-37292 tenda vulnerability CVSS: 0 25 Aug 2022, 16:15 UTC

Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, which satisfies the request of the upper-level interface function sub_430124, that is, handles the post request under /goform/SetIpMacBind.

CVE-2022-37824 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic.

CVE-2022-37823 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSer.

CVE-2022-37822 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic.

CVE-2022-37821 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in the function formSetProvince.

CVE-2022-37820 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysToolDDNS.

CVE-2022-37819 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the function fromSetSysTime.

CVE-2022-37818 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.

CVE-2022-37817 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.

CVE-2022-37816 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.

CVE-2022-37815 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.

CVE-2022-37814 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.

CVE-2022-37813 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.

CVE-2022-37812 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.

CVE-2022-37811 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.

CVE-2022-37810 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

CVE-2022-37809 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.

CVE-2022-37808 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.

CVE-2022-37807 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.

CVE-2022-37806 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.

CVE-2022-37805 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.

CVE-2022-37804 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.

CVE-2022-37803 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.

CVE-2022-37802 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.

CVE-2022-37801 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.

CVE-2022-37800 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.

CVE-2022-37799 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter at the function setSmartPowerManagement.

CVE-2022-37798 tenda vulnerability CVSS: 0 25 Aug 2022, 15:15 UTC

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.

CVE-2022-37175 tenda vulnerability CVSS: 0 19 Aug 2022, 21:15 UTC

Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.

CVE-2022-35201 tenda vulnerability CVSS: 0 19 Aug 2022, 15:15 UTC

Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.

CVE-2022-36273 tenda vulnerability CVSS: 0 16 Aug 2022, 13:15 UTC

Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.

CVE-2022-35561 tenda vulnerability CVSS: 0 12 Aug 2022, 15:15 UTC

A stack overflow vulnerability exists in /goform/WifiMacFilterSet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

CVE-2022-35560 tenda vulnerability CVSS: 0 12 Aug 2022, 15:15 UTC

A stack overflow vulnerability exists in /goform/wifiSSIDset in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

CVE-2022-35559 tenda vulnerability CVSS: 0 12 Aug 2022, 15:15 UTC

A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and ping2 parameters for a stack overflow attack. An attacker can use this vulnerability to execute arbitrary code execution.

CVE-2022-35558 tenda vulnerability CVSS: 0 12 Aug 2022, 15:15 UTC

A stack overflow vulnerability exists in /goform/WifiMacFilterGet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

CVE-2022-35557 tenda vulnerability CVSS: 0 12 Aug 2022, 15:15 UTC

A stack overflow vulnerability exists in /goform/wifiSSIDget in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.

CVE-2022-35555 tenda vulnerability CVSS: 0 12 Aug 2022, 15:15 UTC

A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution.

CVE-2022-32054 tenda vulnerability CVSS: 10.0 07 Jul 2022, 19:15 UTC

Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.

CVE-2022-34597 tenda vulnerability CVSS: 7.5 06 Jul 2022, 17:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

CVE-2022-34596 tenda vulnerability CVSS: 7.5 06 Jul 2022, 17:15 UTC

Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

CVE-2022-34595 tenda vulnerability CVSS: 7.5 06 Jul 2022, 17:15 UTC

Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.

CVE-2022-32043 tenda vulnerability CVSS: 5.0 01 Jul 2022, 18:15 UTC

Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo.

CVE-2022-32041 tenda vulnerability CVSS: 5.0 01 Jul 2022, 18:15 UTC

Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData.

CVE-2022-32040 tenda vulnerability CVSS: 5.0 01 Jul 2022, 18:15 UTC

Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm.

CVE-2022-32039 tenda vulnerability CVSS: 5.0 01 Jul 2022, 18:15 UTC

Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient.

CVE-2022-32037 tenda vulnerability CVSS: 5.0 01 Jul 2022, 18:15 UTC

Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg.

CVE-2022-32036 tenda vulnerability CVSS: 7.8 01 Jul 2022, 18:15 UTC

Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb.

CVE-2022-32035 tenda vulnerability CVSS: 7.8 01 Jul 2022, 18:15 UTC

Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng.

CVE-2022-32034 tenda vulnerability CVSS: 7.8 01 Jul 2022, 18:15 UTC

Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist.

CVE-2022-32033 tenda vulnerability CVSS: 7.8 01 Jul 2022, 18:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the function formSetVirtualSer.

CVE-2022-32032 tenda vulnerability CVSS: 10.0 01 Jul 2022, 18:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule.

CVE-2022-32031 tenda vulnerability CVSS: 7.8 01 Jul 2022, 18:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetRouteStatic.

CVE-2022-32030 tenda vulnerability CVSS: 7.8 01 Jul 2022, 18:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetQosBand.

CVE-2022-30023 tenda vulnerability CVSS: 9.0 16 Jun 2022, 15:15 UTC

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

CVE-2022-30425 tenda vulnerability CVSS: 9.0 02 Jun 2022, 14:15 UTC

Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr parameters. This vulnerability is exploited via a crafted POST request.

CVE-2022-30477 tenda vulnerability CVSS: 7.5 26 May 2022, 16:15 UTC

Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetClientState request.

CVE-2022-30476 tenda vulnerability CVSS: 7.5 26 May 2022, 16:15 UTC

Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetFirewallCfg request.

CVE-2022-30475 tenda vulnerability CVSS: 5.0 26 May 2022, 16:15 UTC

Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/WifiExtraSet request.

CVE-2022-30474 tenda vulnerability CVSS: 7.5 26 May 2022, 16:15 UTC

Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request.

CVE-2022-30473 tenda vulnerability CVSS: 5.0 26 May 2022, 16:15 UTC

Tenda AC Series Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function form_fast_setting_wifi_set

CVE-2022-30472 tenda vulnerability CVSS: 7.5 26 May 2022, 16:15 UTC

Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat

CVE-2021-42659 tenda vulnerability CVSS: 6.1 24 May 2022, 12:15 UTC

There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long list parameter occurs.

CVE-2022-30033 tenda vulnerability CVSS: 7.8 18 May 2022, 20:15 UTC

Tenda TX9 Pro V22.03.02.10 is vulnerable to Buffer Overflow via the functtion setIPv6Status() in httpd module.

CVE-2022-28917 tenda vulnerability CVSS: 7.8 18 May 2022, 16:15 UTC

Tenda AX12 v22.03.01.21_cn was discovered to contain a stack overflow via the lanIp parameter in /goform/AdvSetLanIp.

CVE-2022-30040 tenda vulnerability CVSS: 5.0 11 May 2022, 18:15 UTC

Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bin / tdhttpd in ubif file system, attackers can access http://ip/goform/SetSysTimeCfg, and by setting the ntpserve parameter, the stack buffer overflow can be caused to achieve the effect of router denial of service.

CVE-2022-29591 tenda vulnerability CVSS: 10.0 10 May 2022, 12:15 UTC

Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.

CVE-2022-28973 tenda vulnerability CVSS: 7.8 06 May 2022, 14:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the function fromAdvSetMacMtuWan. This vulnerability allows attackers to cause a Denial of Service (DoS).

CVE-2022-28972 tenda vulnerability CVSS: 7.8 06 May 2022, 14:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS).

CVE-2022-28971 tenda vulnerability CVSS: 7.8 06 May 2022, 14:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetIpMacBind. This vulnerability allows attackers to cause a Denial of Service (DoS).

CVE-2022-28970 tenda vulnerability CVSS: 7.8 06 May 2022, 14:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS).

CVE-2022-28969 tenda vulnerability CVSS: 7.8 06 May 2022, 14:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS).

CVE-2022-29592 tenda vulnerability CVSS: 10.0 05 May 2022, 17:15 UTC

Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).

CVE-2022-28557 tenda vulnerability CVSS: 7.5 04 May 2022, 16:15 UTC

There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution

CVE-2022-28556 tenda vulnerability CVSS: 5.0 04 May 2022, 16:15 UTC

Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in stack overflow. Similarly, this vulnerability can be used together with CVE-2021-44971

CVE-2022-28082 tenda vulnerability CVSS: 7.5 04 May 2022, 14:15 UTC

Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.

CVE-2022-28561 tenda vulnerability CVSS: 10.0 03 May 2022, 16:15 UTC

There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

CVE-2022-28560 tenda vulnerability CVSS: 10.0 03 May 2022, 16:15 UTC

There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

CVE-2022-28572 tenda vulnerability CVSS: 6.5 02 May 2022, 13:15 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function

CVE-2022-27375 tenda vulnerability CVSS: 7.1 25 Apr 2022, 16:16 UTC

Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.

CVE-2022-27374 tenda vulnerability CVSS: 7.1 25 Apr 2022, 16:16 UTC

Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.

CVE-2022-27022 tenda vulnerability CVSS: 10.0 07 Apr 2022, 16:15 UTC

There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload.

CVE-2022-27016 tenda vulnerability CVSS: 10.0 07 Apr 2022, 15:15 UTC

There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.

CVE-2022-26278 tenda vulnerability CVSS: 10.0 28 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

CVE-2022-27083 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.

CVE-2022-27082 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.

CVE-2022-27081 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.

CVE-2022-27080 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.

CVE-2022-27079 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.

CVE-2022-27078 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.

CVE-2022-27077 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.

CVE-2022-27076 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd.

CVE-2022-26536 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools.

CVE-2022-26290 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.

CVE-2022-26289 tenda vulnerability CVSS: 10.0 24 Mar 2022, 00:15 UTC

Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.

CVE-2022-25461 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function.

CVE-2022-25460 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.

CVE-2022-25459 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.

CVE-2022-25458 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function.

CVE-2022-25457 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.

CVE-2022-25456 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function.

CVE-2022-25455 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.

CVE-2022-25454 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.

CVE-2022-25453 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.

CVE-2022-25452 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function.

CVE-2022-25451 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function.

CVE-2022-25450 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.

CVE-2022-25449 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.

CVE-2022-25448 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function.

CVE-2022-25447 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.

CVE-2022-25446 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function.

CVE-2022-25445 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

CVE-2022-25441 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function.

CVE-2022-25440 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.

CVE-2022-25439 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.

CVE-2022-25438 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.

CVE-2022-25437 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.

CVE-2022-25435 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function.

CVE-2022-25434 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function.

CVE-2022-25433 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo function.

CVE-2022-25431 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the Formsetqosband function.

CVE-2022-25429 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function.

CVE-2022-25428 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function.

CVE-2022-25427 tenda vulnerability CVSS: 10.0 18 Mar 2022, 21:15 UTC

Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.

CVE-2022-25566 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

CVE-2022-25561 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42DE00. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

CVE-2022-25560 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_4327CC. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

CVE-2022-25558 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetProvince. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ProvinceCode parameter.

CVE-2022-25557 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the urls parameter.

CVE-2022-25556 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42E328. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

CVE-2022-25555 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ntpServer parameter.

CVE-2022-25554 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceId parameter.

CVE-2022-25553 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsPwd parameter.

CVE-2022-25552 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.

CVE-2022-25551 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsDomain parameter.

CVE-2022-25550 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceName parameter.

CVE-2022-25549 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsEn parameter.

CVE-2022-25548 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the serverName parameter.

CVE-2022-25547 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

CVE-2022-25546 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:47 UTC

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsUser parameter.

CVE-2022-24995 tenda vulnerability CVSS: 7.5 10 Mar 2022, 17:46 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

CVE-2021-46408 tenda vulnerability CVSS: 7.8 10 Mar 2022, 17:44 UTC

Tenda AX12 v22.03.01.21 was discovered to contain a stack buffer overflow in the function sub_422CE4. This vulnerability allows attackers to cause a Denial of Service (DoS) via the strcpy parameter.

CVE-2021-46394 tenda vulnerability CVSS: 7.5 04 Mar 2022, 14:15 UTC

There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check, which causes stack overflow. By POSTing the page /goform/SetPptpServerCfg with proper startIp, the attacker can easily perform remote code execution with carefully crafted overflow data.

CVE-2021-46393 tenda vulnerability CVSS: 7.5 04 Mar 2022, 13:15 UTC

There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security check,which causes stack overflow. By POSTing the page /goform/SetPptpServerCfg with proper startIp, the attacker can easily perform remote code execution with carefully crafted overflow data.

CVE-2022-25418 tenda vulnerability CVSS: 10.0 24 Feb 2022, 15:15 UTC

Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.

CVE-2022-25417 tenda vulnerability CVSS: 10.0 24 Feb 2022, 15:15 UTC

Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.

CVE-2022-25414 tenda vulnerability CVSS: 10.0 24 Feb 2022, 15:15 UTC

Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.

CVE-2021-45391 tenda vulnerability CVSS: 5.0 16 Feb 2022, 14:15 UTC

A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/setIPv6Status binary file /usr/sbin/httpd via the conType parameter, which causes a Denial of Service.

CVE-2021-46321 tenda vulnerability CVSS: 7.5 15 Feb 2022, 20:15 UTC

Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiBasicCfg module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2021-46265 tenda vulnerability CVSS: 7.5 15 Feb 2022, 20:15 UTC

Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wanBasicCfg module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2021-46264 tenda vulnerability CVSS: 7.5 15 Feb 2022, 20:15 UTC

Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the onlineList module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2021-46263 tenda vulnerability CVSS: 7.5 15 Feb 2022, 20:15 UTC

Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiTime module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2021-46262 tenda vulnerability CVSS: 7.5 15 Feb 2022, 20:15 UTC

Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2021-45392 tenda vulnerability CVSS: 7.8 14 Feb 2022, 17:15 UTC

A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service.

CVE-2020-26728 tenda vulnerability CVSS: 7.5 11 Feb 2022, 19:15 UTC

A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request.

CVE-2022-24163 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.

CVE-2022-24162 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

CVE-2022-24161 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a heap overflow in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mac parameter.

CVE-2022-24160 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetDeviceName. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.

CVE-2022-24159 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetPPTPServer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the startIp and endIp parameters.

CVE-2022-24158 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetIpMacBind. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

CVE-2022-24157 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetMacFilterCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceList parameter.

CVE-2022-24156 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

CVE-2022-24155 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a heap overflow in the function setSchedWifi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the schedStartTime and schedEndTime parameters.

CVE-2022-24154 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetRebootTimer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the rebootTime parameter.

CVE-2022-24153 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formAddMacfilterRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.

CVE-2022-24152 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetRouteStatic. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

CVE-2022-24151 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS) via the shareSpeed parameter.

CVE-2022-24150 tenda vulnerability CVSS: 7.5 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebMan. This vulnerability allows attackers to execute arbitrary commands via the remoteIp parameter.

CVE-2022-24149 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWirelessRepeat. This vulnerability allows attackers to cause a Denial of Service (DoS) via the wpapsk_crypto parameter.

CVE-2022-24148 tenda vulnerability CVSS: 7.5 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers to execute arbitrary commands via the dmzIp parameter.

CVE-2022-24147 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromAdvSetMacMtuWan. This vulnerability allows attackers to cause a Denial of Service (DoS) via the wanMTU, wanSpeed, cloneType, mac, and serviceName parameters.

CVE-2022-24146 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetQosBand. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

CVE-2022-24145 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formWifiBasicSet. This vulnerability allows attackers to cause a Denial of Service (DoS) via the security and security_5g parameters.

CVE-2022-24144 tenda vulnerability CVSS: 7.5 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. This vulnerability allows attackers to execute arbitrary commands via the gateway, dns1, and dns2 parameters.

CVE-2022-24143 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN and AX12 22.03.01.2_CN was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.

CVE-2022-24142 tenda vulnerability CVSS: 7.8 04 Feb 2022, 02:15 UTC

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the firewallEn parameter.

CVE-2021-44971 tenda vulnerability CVSS: 7.5 28 Jan 2022, 19:15 UTC

Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.

CVE-2021-31758 tenda vulnerability CVSS: 10.0 07 May 2021, 23:15 UTC

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request.

CVE-2021-31757 tenda vulnerability CVSS: 10.0 07 May 2021, 23:15 UTC

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows attackers to execute arbitrary code on the system via a crafted post request.

CVE-2021-31756 tenda vulnerability CVSS: 10.0 07 May 2021, 23:15 UTC

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitrary code on the system via a crafted post request. This occurs when input vector controlled by malicious attack get copied to the stack variable.

CVE-2021-31755 tenda vulnerability CVSS: 10.0 07 May 2021, 23:15 UTC

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

CVE-2021-27707 tenda vulnerability CVSS: 7.5 14 Apr 2021, 15:15 UTC

Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.

CVE-2021-27706 tenda vulnerability CVSS: 7.5 14 Apr 2021, 15:15 UTC

Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the parameter "IPMacBindIndex" to strcpy without limit.

CVE-2021-27705 tenda vulnerability CVSS: 7.5 14 Apr 2021, 15:15 UTC

Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"qosIndex "request. This occurs because the "formQOSRuleDel" function directly passes the parameter "qosIndex" to strcpy without limit.

CVE-2021-3186 tenda vulnerability CVSS: 4.3 26 Jan 2021, 18:16 UTC

A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter.

CVE-2020-35391 tenda vulnerability CVSS: 3.3 01 Jan 2021, 07:15 UTC

Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.

CVE-2020-28095 tenda vulnerability CVSS: 7.8 30 Dec 2020, 21:15 UTC

On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.

CVE-2020-15916 tenda vulnerability CVSS: 10.0 23 Jul 2020, 18:15 UTC

goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.

CVE-2020-10989 tenda vulnerability CVSS: 4.3 13 Jul 2020, 19:15 UTC

An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.

CVE-2020-10988 tenda vulnerability CVSS: 10.0 13 Jul 2020, 19:15 UTC

A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.

CVE-2020-10987 tenda vulnerability CVSS: 10.0 13 Jul 2020, 19:15 UTC

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

CVE-2020-10986 tenda vulnerability CVSS: 7.1 13 Jul 2020, 18:15 UTC

A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.

CVE-2019-16288 tenda vulnerability CVSS: 7.8 13 Sep 2019, 15:15 UTC

On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the device to crash.

CVE-2018-14559 tenda vulnerability CVSS: 7.8 25 Apr 2019, 20:29 UTC

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.

CVE-2018-14557 tenda vulnerability CVSS: 7.8 25 Apr 2019, 20:29 UTC

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, a causing buffer overflow.

CVE-2018-14558 tenda vulnerability CVSS: 10.0 30 Oct 2018, 18:29 UTC

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.

CVE-2018-18732 tenda vulnerability CVSS: 7.8 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVE-2018-18731 tenda vulnerability CVSS: 7.8 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

CVE-2018-18730 tenda vulnerability CVSS: 7.8 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

CVE-2018-18729 tenda vulnerability CVSS: 9.0 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy to a variable placed on the heap, which can leak sensitive information or even hijack program control flow.

CVE-2018-18728 tenda vulnerability CVSS: 7.5 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.

CVE-2018-18727 tenda vulnerability CVSS: 7.8 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVE-2018-18709 tenda vulnerability CVSS: 7.8 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVE-2018-18708 tenda vulnerability CVSS: 7.8 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

CVE-2018-18707 tenda vulnerability CVSS: 7.8 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVE-2018-18706 tenda vulnerability CVSS: 7.8 29 Oct 2018, 12:29 UTC

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

CVE-2017-16936 tenda vulnerability CVSS: 3.3 24 Nov 2017, 07:29 UTC

Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to read arbitrary files via a cgi-bin/luci/request?op=1&path= URI that uses directory traversal sequences after a /usb/ substring.

CVE-2017-16923 tenda vulnerability CVSS: 8.3 21 Nov 2017, 14:29 UTC

Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to execute arbitrary OS commands via a crafted cgi-bin/luci/usbeject?dev_name= GET request from the LAN. This occurs because the "sub_A6E8 usbeject_process_entry" function executes a system function with untrusted input.

CVE-2017-14515 tenda vulnerability CVSS: 5.0 17 Sep 2017, 22:29 UTC

Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service (temporary HTTP outage and forced logout) via unspecified vectors.

CVE-2017-14514 tenda vulnerability CVSS: 5.0 17 Sep 2017, 22:29 UTC

Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a crafted URL.

CVE-2015-5995 tenda vulnerability CVSS: 10.0 31 Dec 2015, 05:59 UTC

Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.

CVE-2014-7281 tenda vulnerability CVSS: 6.8 23 Oct 2014, 14:55 UTC

Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

CVE-2014-5246 tenda vulnerability CVSS: 10.0 22 Aug 2014, 14:55 UTC

The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.