Show filters
1,150 Total Results
Displaying 31-40 of 1,150
Sort by:
Attacker Value
Unknown
CVE-2024-10282
Disclosure Date: October 23, 2024 (last updated November 02, 2024)
A vulnerability classified as critical was found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected by this vulnerability is the function sub_42EA38 of the file /goform/SetVirtualServerCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-10281
Disclosure Date: October 23, 2024 (last updated November 02, 2024)
A vulnerability classified as critical has been found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected is the function sub_42EEE0 of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-10280
Disclosure Date: October 23, 2024 (last updated November 02, 2024)
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-10130
Disclosure Date: October 18, 2024 (last updated October 29, 2024)
A vulnerability classified as critical was found in Tenda AC8 16.03.34.06. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-10123
Disclosure Date: October 18, 2024 (last updated October 29, 2024)
A vulnerability was found in Tenda AC8 16.03.34.06. It has been declared as critical. Affected by this vulnerability is the function compare_parentcontrol_time of the file /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This is not the same issue like CVE-2023-33671. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-9793
Disclosure Date: October 10, 2024 (last updated November 02, 2024)
A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-46628
Disclosure Date: September 26, 2024 (last updated October 05, 2024)
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.
0
Attacker Value
Unknown
CVE-2024-46049
Disclosure Date: September 13, 2024 (last updated September 20, 2024)
Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.
0
Attacker Value
Unknown
CVE-2024-46048
Disclosure Date: September 13, 2024 (last updated September 20, 2024)
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
0
Attacker Value
Unknown
CVE-2024-46047
Disclosure Date: September 13, 2024 (last updated September 20, 2024)
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.
0