Filtered by vendor Tenda Subscriptions
Total 1384 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-42165 1 Tenda 2 Ac10, Ac10 Firmware 2025-05-13 9.8 Critical
Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.
CVE-2022-43260 1 Tenda 2 Ac18, Ac18 Firmware 2025-05-12 9.8 Critical
Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.
CVE-2022-43259 1 Tenda 2 Ac15, Ac15 Firmware 2025-05-12 7.5 High
Tenda AC15 V15.03.05.18 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function.
CVE-2024-0541 1 Tenda 2 W9, W9 Firmware 2025-05-12 8.8 High
A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. Affected by this vulnerability is the function formAddSysLogRule of the component httpd. The manipulation of the argument sysRulenEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250711. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2022-43026 1 Tenda 2 Tx3, Tx3 Firmware 2025-05-09 9.8 Critical
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.
CVE-2022-43025 1 Tenda 2 Tx3, Tx3 Firmware 2025-05-09 9.8 Critical
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.
CVE-2022-43024 1 Tenda 2 Tx3, Tx3 Firmware 2025-05-09 9.8 Critical
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
CVE-2022-43029 1 Tenda 2 Tx3, Tx3 Firmware 2025-05-08 9.8 Critical
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the time parameter at /goform/SetSysTimeCfg.
CVE-2022-43028 1 Tenda 2 Tx3, Tx3 Firmware 2025-05-08 9.8 Critical
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at /goform/SetSysTimeCfg.
CVE-2022-43027 1 Tenda 2 Tx3, Tx3 Firmware 2025-05-08 9.8 Critical
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter at /goform/SetFirewallCfg.
CVE-2025-28221 1 Tenda 2 W6-s, W6-s Firmware 2025-05-08 7.5 High
Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the set_local_time function, which allows remote attackers to cause web server crash via parameter time passed to the binary through a POST request.
CVE-2022-42233 1 Tenda 2 11n, 11n Firmware 2025-05-08 9.8 Critical
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
CVE-2025-25662 1 Tenda 2 O4, O4 Firmware 2025-05-07 9.8 Critical
Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via the argument remark/type/time.
CVE-2022-40876 1 Tenda 2 Ax1803, Ax1803 Firmware 2025-05-07 9.8 Critical
In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).
CVE-2022-40875 1 Tenda 2 Ax1803, Ax1803 Firmware 2025-05-07 7.5 High
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.
CVE-2022-40874 1 Tenda 2 Ax1803, Ax1803 Firmware 2025-05-07 7.5 High
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.
CVE-2025-45042 1 Tenda 2 Ac9, Ac9 Firmware 2025-05-07 9.8 Critical
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
CVE-2025-28220 1 Tenda 2 W6-s, W6-s Firmware 2025-05-06 7.5 High
Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash via parameter funcpara1 passed to the binary through a POST request.
CVE-2023-27076 1 Tenda 2 G103, G103 Firmware 2025-05-05 9.8 Critical
Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.
CVE-2022-43108 1 Tenda 2 Ac23, Ac23 Firmware 2025-05-05 9.8 Critical
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.