Skip to main content

Vendor/product archive

tenda / w15e CVEs

Beta · best-effort

33 CVEs tagged to tenda / w15e3 Critical, 26 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-30140

Published Mar 9, 2026

An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-4127

Published Apr 24, 2024

A vulnerability was found in Tenda W15E 15.11.0.14. It has been classified as critical. Affected is the function guestWifiRuleRefresh. The manipulation of the argument qosGuestDow…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4126

Published Apr 24, 2024

A vulnerability was found in Tenda W15E 15.11.0.14 and classified as critical. This issue affects the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4125

Published Apr 24, 2024

A vulnerability has been found in Tenda W15E 15.11.0.14 and classified as critical. This vulnerability affects the function formSetStaticRoute of the file /goform/setStaticRoute.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4124

Published Apr 24, 2024

A vulnerability, which was classified as critical, was found in Tenda W15E 15.11.0.14. This affects the function formSetRemoteWebManage of the file /goform/SetRemoteWebManage. The…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4123

Published Apr 24, 2024

A vulnerability, which was classified as critical, has been found in Tenda W15E 15.11.0.14. Affected by this issue is the function formSetPortMapping of the file /goform/SetPortMa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4122

Published Apr 24, 2024

A vulnerability classified as critical was found in Tenda W15E 15.11.0.14. Affected by this vulnerability is the function formSetDebugCfg of the file /goform/setDebugCfg. The mani…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4121

Published Apr 24, 2024

A vulnerability classified as critical has been found in Tenda W15E 15.11.0.14. Affected is the function formQOSRuleDel. The manipulation of the argument qosIndex leads to stack-b…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4120

Published Apr 24, 2024

A vulnerability was found in Tenda W15E 15.11.0.14. It has been rated as critical. This issue affects the function formIPMacBindModify of the file /goform/modifyIpMacBind. The man…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4119

Published Apr 24, 2024

A vulnerability was found in Tenda W15E 15.11.0.14. It has been declared as critical. This vulnerability affects the function formIPMacBindDel of the file /goform/delIpMacBind. Th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4118

Published Apr 24, 2024

A vulnerability was found in Tenda W15E 15.11.0.14. It has been classified as critical. This affects the function formIPMacBindAdd of the file /goform/addIpMacBind. The manipulati…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4117

Published Apr 24, 2024

A vulnerability was found in Tenda W15E 15.11.0.14 and classified as critical. Affected by this issue is the function formDelPortMapping of the file /goform/DelPortMapping. The ma…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4116

Published Apr 24, 2024

A vulnerability has been found in Tenda W15E 15.11.0.14 and classified as critical. Affected by this vulnerability is the function formDelDhcpRule of the file /goform/DelDhcpRule.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4115

Published Apr 24, 2024

A vulnerability, which was classified as critical, was found in Tenda W15E 15.11.0.14. Affected is the function formAddDnsForward of the file /goform/AddDnsForward. The manipulati…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27065

Published Mar 13, 2023

Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27064

Published Mar 13, 2023

Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. This vulnerability a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27063

Published Mar 13, 2023

Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vuln…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-27062

Published Mar 13, 2023

Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulnerability allows attackers to cause a De…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27061

Published Mar 13, 2023

Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. T…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-42060

Published Nov 15, 2022

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42058

Published Nov 15, 2022

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a D…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-42053

Published Nov 15, 2022

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41396

Published Nov 15, 2022

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet an…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2