Skip to main content

Vendor archive

tenda CVEs

Beta · best-effort

1,846 CVEs tagged to vendor tenda551 Critical, 1,064 High, 194 Medium, 37 Low, 0 Unrated.

CVE-2022-24149

Published Feb 4, 2022

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWirelessRepeat. This vulnerability allows attackers to cause a Denial of Service (DoS)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24148

Published Feb 4, 2022

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers to execute arbitrary commands…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24147

Published Feb 4, 2022

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromAdvSetMacMtuWan. This vulnerability allows attackers to cause a Denial of Service (DoS) vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24146

Published Feb 4, 2022

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetQosBand. This vulnerability allows attackers to cause a Denial of Service (DoS) via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24145

Published Feb 4, 2022

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formWifiBasicSet. This vulnerability allows attackers to cause a Denial of Service (DoS) via t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24144

Published Feb 4, 2022

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. This vulnerability allows attackers to execute arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24142

Published Feb 4, 2022

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31758

Published May 7, 2021

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-31757

Published May 7, 2021

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows attackers to execute arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-31756

Published May 7, 2021

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-31755

Published May 7, 2021

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
46.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-3186

Published Jan 26, 2021

A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35391

Published Jan 1, 2021

Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/Rout…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28095

Published Dec 30, 2020

On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15916

Published Jul 23, 2020

goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parame…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10989

Published Jul 13, 2020

An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10988

Published Jul 13, 2020

A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10987

Published Jul 13, 2020

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
57.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-10986

Published Jul 13, 2020

A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16288

Published Sep 13, 2019

On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the device to crash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,801-1,825 of 1,846 CVEsPage 73 of 74