Show filters
81 Total Results
Displaying 1-10 of 81
Sort by:
Attacker Value
Unknown
CVE-2021-40546
Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi.
1
Attacker Value
Unknown
CVE-2025-25343
Disclosure Date: February 12, 2025 (last updated February 20, 2025)
Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
0
Attacker Value
Unknown
CVE-2024-52714
Disclosure Date: November 19, 2024 (last updated November 21, 2024)
Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
0
Attacker Value
Unknown
CVE-2024-10698
Disclosure Date: November 02, 2024 (last updated November 05, 2024)
A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-10697
Disclosure Date: November 02, 2024 (last updated November 05, 2024)
A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument The leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-10280
Disclosure Date: October 23, 2024 (last updated November 02, 2024)
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2023-38823
Disclosure Date: November 20, 2023 (last updated November 29, 2023)
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
0
Attacker Value
Unknown
CVE-2023-40830
Disclosure Date: October 03, 2023 (last updated October 09, 2023)
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
0
Attacker Value
Unknown
CVE-2023-40848
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "sub_7D858."
0
Attacker Value
Unknown
CVE-2023-40847
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "initIpAddrInfo." In the function, it reads in a user-provided parameter, and the variable is passed to the function without any length check.
0