Vulnerabilities (CVE)

Filtered by vendor Tenda Subscribe
Total 1717 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-12274 1 Tenda 2 Ch22, Ch22 Firmware 2025-10-28 9.0 HIGH 8.8 HIGH
A security vulnerability has been detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
CVE-2025-12234 1 Tenda 2 Ch22, Ch22 Firmware 2025-10-27 9.0 HIGH 8.8 HIGH
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-12235 1 Tenda 2 Ch22, Ch22 Firmware 2025-10-27 7.7 HIGH 8.0 HIGH
A vulnerability was found in Tenda CH22 1.0.0.1. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in buffer overflow. The attack must originate from the local network. The exploit has been made public and could be used.
CVE-2025-60339 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-27 N/A 7.5 HIGH
Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the schedStartTime and schedEndTime parameters.
CVE-2025-60337 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-27 N/A 7.5 HIGH
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-60343 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-24 N/A 7.5 HIGH
Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the wanMTU, wanSpeed, cloneType, mac, serviceName, serverName, wanMTU2, wanSpeed2, cloneType2, mac2, serviceName2, and serverName2 parameters.
CVE-2025-60338 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-23 N/A 7.5 HIGH
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-60342 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-23 N/A 7.5 HIGH
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-8958 1 Tenda 2 Tx3, Tx3 Firmware 2025-10-21 9.0 HIGH 8.8 HIGH
A vulnerability was identified in Tenda TX3 16.03.13.11_multi_TDE01. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11550 1 Tenda 2 W12, W12 Firmware 2025-10-20 6.8 MEDIUM 6.5 MEDIUM
A vulnerability was found in Tenda W12 3.0.0.6(3948). The impacted element is the function wifiScheduledSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument wifiScheduledSet results in null pointer dereference. The attack may be performed from remote. The exploit has been made public and could be used.
CVE-2025-11586 1 Tenda 2 Ac7, Ac7 Firmware 2025-10-20 9.0 HIGH 8.8 HIGH
A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-11549 1 Tenda 2 W12, W12 Firmware 2025-10-18 9.0 HIGH 8.8 HIGH
A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11525 1 Tenda 2 Ac7, Ac7 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11523 1 Tenda 2 Ac7, Ac7 Firmware 2025-10-09 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of the argument lanIp results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
CVE-2025-11524 1 Tenda 2 Ac7, Ac7 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCfg. This manipulation of the argument ddnsEn causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.
CVE-2025-11528 1 Tenda 2 Ac7, Ac7 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQos. The manipulation of the argument enable leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
CVE-2025-11356 1 Tenda 2 Ac23, Ac23 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVE-2025-11385 1 Tenda 2 Ac20, Ac20 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The affected element is the function sscanf of the file /goform/fast_setting_wifi_set. The manipulation of the argument timeZone leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11386 1 Tenda 2 Ac15, Ac15 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability was found in Tenda AC15 15.03.05.18. The impacted element is an unknown function of the file /goform/SetDDNSCfg of the component POST Parameter Handler. The manipulation of the argument ddnsEn results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
CVE-2025-11387 1 Tenda 2 Ac15, Ac15 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability was determined in Tenda AC15 15.03.05.18. This affects an unknown function of the file /goform/fast_setting_pppoe_set. This manipulation of the argument Password causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.