Show filters
145 Total Results
Displaying 131-140 of 145
Sort by:
Attacker Value
Unknown

CVE-2020-13389

Disclosure Date: May 22, 2020 (last updated February 21, 2025)
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/openSchedWifi schedStartTime and schedEndTime parameters for a POST request, a value is directly used in a strcpy to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.
Attacker Value
Unknown

CVE-2019-5071

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU). A specially crafted HTTP POST request can cause a command injection in the DNS1 post parameters, resulting in code execution. An attacker can send HTTP POST request with command to trigger this vulnerability.
Attacker Value
Unknown

CVE-2019-5072

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU). A specially crafted HTTP POST request can cause a command injection in the DNS2 post parameters, resulting in code execution. An attacker can send HTTP POST request with command to trigger this vulnerability.
Attacker Value
Unknown

CVE-2019-16412

Disclosure Date: September 19, 2019 (last updated November 27, 2024)
In goform/setSysTools on Tenda N301 wireless routers, attackers can trigger a device crash via a zero wanMTU value. (Prohibition of this zero value is only enforced within the GUI.)
Attacker Value
Unknown

CVE-2018-20373

Disclosure Date: December 23, 2018 (last updated November 27, 2024)
Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client.
0
Attacker Value
Unknown

CVE-2018-16334

Disclosure Date: September 02, 2018 (last updated November 27, 2024)
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.
0
Attacker Value
Unknown

CVE-2018-16333

Disclosure Date: September 02, 2018 (last updated November 27, 2024)
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server. While processing the ssid parameter for a POST request, the value is directly used in a sprintf call to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.
0
Attacker Value
Unknown

CVE-2018-14497

Disclosure Date: August 04, 2018 (last updated November 27, 2024)
Tenda D152 ADSL routers allow XSS via a crafted SSID.
0
Attacker Value
Unknown

CVE-2018-14492

Disclosure Date: July 21, 2018 (last updated November 27, 2024)
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
0
Attacker Value
Unknown

CVE-2018-5768

Disclosure Date: March 20, 2018 (last updated November 26, 2024)
A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted password parameter for the COOKIE header.
0