Show filters
1,150 Total Results
Displaying 1-10 of 1,150
Sort by:
Attacker Value
Unknown

CVE-2021-40546

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi.
Attacker Value
Unknown

CVE-2025-25343

Disclosure Date: February 12, 2025 (last updated February 20, 2025)
Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
Attacker Value
Unknown

CVE-2025-0848

Disclosure Date: January 30, 2025 (last updated January 30, 2025)
A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The manipulation of the argument wpapsk_crypto5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2025-0566

Disclosure Date: January 19, 2025 (last updated January 19, 2025)
A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13. This affects the function formSetDevNetName of the file /goform/SetDevNetName. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2025-0528

Disclosure Date: January 17, 2025 (last updated January 18, 2025)
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-57583

Disclosure Date: January 16, 2025 (last updated January 23, 2025)
Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.
Attacker Value
Unknown

CVE-2024-57575

Disclosure Date: January 16, 2025 (last updated January 23, 2025)
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
Attacker Value
Unknown

CVE-2025-0349

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
0
Attacker Value
Unknown

CVE-2024-52275

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromWizardHandle modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50.
0
Attacker Value
Unknown

CVE-2024-52274

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoubleL2tpConfig->guest_ip_check(overflow arg: mask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50
0