Show filters
145 Total Results
Displaying 1-10 of 145
Sort by:
Attacker Value
Unknown

CVE-2024-50854

Disclosure Date: November 13, 2024 (last updated November 15, 2024)
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.
Attacker Value
Unknown

CVE-2024-50853

Disclosure Date: November 13, 2024 (last updated November 15, 2024)
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.
Attacker Value
Unknown

CVE-2024-50852

Disclosure Date: November 13, 2024 (last updated November 15, 2024)
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.
Attacker Value
Unknown

CVE-2024-46628

Disclosure Date: September 26, 2024 (last updated October 05, 2024)
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.
Attacker Value
Unknown

CVE-2024-8224

Disclosure Date: August 27, 2024 (last updated December 18, 2024)
A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.20. This issue affects the function formSetDebugCfg of the file /goform/setDebugCfg. The manipulation of the argument enable/level/module leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-42954

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42953

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPW parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42949

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42945

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromAddressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42942

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.