Vulnerabilities (CVE)

Filtered by vendor Tenda Subscribe
Total 1846 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-6113 1 Tenda 2 Fh1203, Fh1203 Firmware 2026-06-17 9.0 HIGH 8.8 HIGH
A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-6112 1 Tenda 2 Fh1205, Fh1205 Firmware 2026-06-17 9.0 HIGH 8.8 HIGH
A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-6111 1 Tenda 2 Fh1205, Fh1205 Firmware 2026-06-17 9.0 HIGH 8.8 HIGH
A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-6110 1 Tenda 2 Fh1201, Fh1201 Firmware 2026-06-17 9.0 HIGH 8.8 HIGH
A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-69766 1 Tenda 2 Ax3, Ax3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.
CVE-2025-69765 1 Tenda 2 Ax3, Ax3 Firmware 2026-06-17 N/A 7.5 HIGH
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.
CVE-2025-69764 1 Tenda 2 Ax3, Ax3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.
CVE-2025-69763 1 Tenda 2 Ax3, Ax3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.
CVE-2025-69762 1 Tenda 2 Ax3, Ax3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote code execution.
CVE-2025-69700 1 Tenda 2 Fh1203, Fh1203 Firmware 2026-06-17 N/A 7.5 HIGH
Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.
CVE-2025-67074 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 6.5 MEDIUM
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serverName`) to /goform/AdvSetMacMtuWan.
CVE-2025-67073 1 Tenda 2 Ac10, Ac10 Firmware 2026-06-17 N/A 9.8 CRITICAL
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.
CVE-2025-65804 1 Tenda 2 Ax3, Ax3 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corruption and enable remote code execution (RCE).
CVE-2025-65226 1 Tenda 2 Ac21, Ac21 Firmware 2026-06-17 N/A 4.3 MEDIUM
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.
CVE-2025-65223 1 Tenda 2 Ac21, Ac21 Firmware 2026-06-17 N/A 4.3 MEDIUM
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.
CVE-2025-65222 1 Tenda 2 Ac21, Ac21 Firmware 2026-06-17 N/A 4.3 MEDIUM
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.
CVE-2025-65221 1 Tenda 2 Ac21, Ac21 Firmware 2026-06-17 N/A 4.3 MEDIUM
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.
CVE-2025-65220 1 Tenda 2 Ac21, Ac21 Firmware 2026-06-17 N/A 4.3 MEDIUM
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.
CVE-2025-63835 1 Tenda 2 Ac18, Ac18 Firmware 2026-06-17 N/A 8.8 HIGH
A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.
CVE-2025-63834 1 Tenda 2 Ac18, Ac18 Firmware 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.