Show filters
113 Total Results
Displaying 91-100 of 113
Sort by:
Attacker Value
Unknown

CVE-2021-38278

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.
Attacker Value
Unknown

CVE-2021-44262

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.
Attacker Value
Unknown

CVE-2021-44261

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device.
Attacker Value
Unknown

CVE-2021-45401

Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client controlled "deviceName" value is passed directly to the "doSystemCmd" function.
Attacker Value
Unknown

CVE-2020-22079

Disclosure Date: October 29, 2021 (last updated February 23, 2025)
Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.
Attacker Value
Unknown

CVE-2021-38532

Disclosure Date: August 11, 2021 (last updated November 28, 2024)
NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings.
Attacker Value
Unknown

CVE-2021-35973

Disclosure Date: June 30, 2021 (last updated February 22, 2025)
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This directly allows the attacker to change the web UI password, and eventually to enable debug mode (telnetd) and gain a shell on the device as the admin limited-user account (however, escalation to root is simple because of weak permissions on the /etc/ directory).
Attacker Value
Unknown

CVE-2020-35788

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user.
Attacker Value
Unknown

CVE-2018-14559

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.
0
Attacker Value
Unknown

CVE-2018-14557

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, a causing buffer overflow.
0