Skip to main content

Vendor/product archive

tenda / ac15_firmware CVEs

Beta · best-effort

85 CVEs tagged to tenda / ac15_firmware25 Critical, 48 High, 11 Medium, 1 Low, 0 Unrated.

CVE-2022-28557

Published May 4, 2022

There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28556

Published May 4, 2022

Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15916

Published Jul 23, 2020

goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parame…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10989

Published Jul 13, 2020

An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10988

Published Jul 13, 2020

A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10987

Published Jul 13, 2020

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
58.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-10986

Published Jul 13, 2020

A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 85 CVEsPage 3 of 4