Show filters
39 Total Results
Displaying 21-30 of 39
Sort by:
Attacker Value
Unknown
CVE-2022-40853
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set
0
Attacker Value
Unknown
CVE-2022-38326
Disclosure Date: September 15, 2022 (last updated October 08, 2023)
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.
0
Attacker Value
Unknown
CVE-2022-38325
Disclosure Date: September 15, 2022 (last updated October 08, 2023)
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.
0
Attacker Value
Unknown
CVE-2020-15916
Disclosure Date: July 23, 2020 (last updated February 21, 2025)
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
0
Attacker Value
Unknown
CVE-2020-10987
Disclosure Date: July 13, 2020 (last updated February 21, 2025)
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
0
Attacker Value
Unknown
CVE-2020-10989
Disclosure Date: July 13, 2020 (last updated February 21, 2025)
An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.
0
Attacker Value
Unknown
CVE-2020-10988
Disclosure Date: July 13, 2020 (last updated February 21, 2025)
A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.
0
Attacker Value
Unknown
CVE-2020-10986
Disclosure Date: July 13, 2020 (last updated February 21, 2025)
A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.
0
Attacker Value
Unknown
CVE-2018-18709
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
0
Attacker Value
Unknown
CVE-2018-18727
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
0