Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2024-3874

Disclosure Date: April 16, 2024 (last updated February 26, 2025)
A vulnerability was found in Tenda W20E 15.11.0.6. It has been declared as critical. This vulnerability affects the function formSetRemoteWebManage of the file /goform/SetRemoteWebManage. The manipulation of the argument remoteIP leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260908. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2023-26806

Disclosure Date: March 19, 2023 (last updated February 24, 2025)
Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,
Attacker Value
Unknown

CVE-2023-26805

Disclosure Date: March 19, 2023 (last updated February 24, 2025)
Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.
Attacker Value
Unknown

CVE-2022-48130

Disclosure Date: February 02, 2023 (last updated February 24, 2025)
Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN.
Attacker Value
Unknown

CVE-2022-45997

Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.
Attacker Value
Unknown

CVE-2022-45996

Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
Attacker Value
Unknown

CVE-2022-40868

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/
Attacker Value
Unknown

CVE-2022-40867

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/
Attacker Value
Unknown

CVE-2022-40866

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/
Attacker Value
Unknown

CVE-2022-40855

Disclosure Date: September 23, 2022 (last updated February 24, 2025)
Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code Execution (RCE) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.