Show filters
87 Total Results
Displaying 41-50 of 87
Sort by:
Attacker Value
Unknown

CVE-2022-40862

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting
Attacker Value
Unknown

CVE-2022-40860

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList
Attacker Value
Unknown

CVE-2022-40853

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set
Attacker Value
Unknown

CVE-2022-38326

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.
Attacker Value
Unknown

CVE-2022-38325

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.
Attacker Value
Unknown

CVE-2022-37175

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.
Attacker Value
Unknown

CVE-2022-28557

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution
Attacker Value
Unknown

CVE-2022-28556

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in stack overflow. Similarly, this vulnerability can be used together with CVE-2021-44971
Attacker Value
Unknown

CVE-2021-44971

Disclosure Date: January 28, 2022 (last updated February 23, 2025)
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
Attacker Value
Unknown

CVE-2021-44352

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.