Show filters
145 Total Results
Displaying 111-120 of 145
Sort by:
Attacker Value
Unknown

CVE-2021-45987

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.
Attacker Value
Unknown

CVE-2021-45986

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.
Attacker Value
Unknown

CVE-2021-44352

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.
Attacker Value
Unknown

CVE-2021-31624

Disclosure Date: October 29, 2021 (last updated February 23, 2025)
Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the urls parameter.
Attacker Value
Unknown

CVE-2020-22079

Disclosure Date: October 29, 2021 (last updated February 23, 2025)
Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.
Attacker Value
Unknown

CVE-2021-31627

Disclosure Date: October 29, 2021 (last updated February 23, 2025)
Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the index parameter.
Attacker Value
Unknown

CVE-2020-20746

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.
Attacker Value
Unknown

CVE-2021-27692

Disclosure Date: April 16, 2021 (last updated February 22, 2025)
Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted "action/umountUSBPartition" request. This occurs because the "formSetUSBPartitionUmount" function executes the "doSystemCmd" function with untrusted input.
Attacker Value
Unknown

CVE-2021-27691

Disclosure Date: April 16, 2021 (last updated February 22, 2025)
Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.
Attacker Value
Unknown

CVE-2020-28093

Disclosure Date: December 28, 2020 (last updated November 28, 2024)
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.