Vulnerabilities (CVE)

Filtered by vendor Tenda Subscribe
Total 1831 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-12234 1 Tenda 2 Ch22, Ch22 Firmware 2025-10-27 9.0 HIGH 8.8 HIGH
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-60339 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-27 N/A 7.5 HIGH
Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the schedStartTime and schedEndTime parameters.
CVE-2025-60337 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-27 N/A 7.5 HIGH
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-60343 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-24 N/A 7.5 HIGH
Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the wanMTU, wanSpeed, cloneType, mac, serviceName, serverName, wanMTU2, wanSpeed2, cloneType2, mac2, serviceName2, and serverName2 parameters.
CVE-2025-60338 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-23 N/A 7.5 HIGH
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-60342 1 Tenda 2 Ac6, Ac6 Firmware 2025-10-23 N/A 7.5 HIGH
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-8958 1 Tenda 2 Tx3, Tx3 Firmware 2025-10-21 9.0 HIGH 8.8 HIGH
A vulnerability was identified in Tenda TX3 16.03.13.11_multi_TDE01. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11586 1 Tenda 2 Ac7, Ac7 Firmware 2025-10-20 9.0 HIGH 8.8 HIGH
A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-11549 1 Tenda 2 W12, W12 Firmware 2025-10-18 9.0 HIGH 8.8 HIGH
A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11525 1 Tenda 2 Ac7, Ac7 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11524 1 Tenda 2 Ac7, Ac7 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCfg. This manipulation of the argument ddnsEn causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.
CVE-2025-11528 1 Tenda 2 Ac7, Ac7 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQos. The manipulation of the argument enable leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
CVE-2025-11356 1 Tenda 2 Ac23, Ac23 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVE-2025-11385 1 Tenda 2 Ac20, Ac20 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The affected element is the function sscanf of the file /goform/fast_setting_wifi_set. The manipulation of the argument timeZone leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11386 1 Tenda 2 Ac15, Ac15 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability was found in Tenda AC15 15.03.05.18. The impacted element is an unknown function of the file /goform/SetDDNSCfg of the component POST Parameter Handler. The manipulation of the argument ddnsEn results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
CVE-2025-11387 1 Tenda 2 Ac15, Ac15 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability was determined in Tenda AC15 15.03.05.18. This affects an unknown function of the file /goform/fast_setting_pppoe_set. This manipulation of the argument Password causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-11388 1 Tenda 2 Ac15, Ac15 Firmware 2025-10-09 9.0 HIGH 8.8 HIGH
A vulnerability was identified in Tenda AC15 15.03.05.18. This impacts an unknown function of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.
CVE-2025-11418 1 Tenda 2 Ch22, Ch22 Firmware 2025-10-09 10.0 HIGH 9.8 CRITICAL
A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component HTTP Request Handler. The manipulation of the argument mit_ssid_index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
CVE-2025-60660 1 Tenda 2 Ac18, Ac18 Firmware 2025-10-07 N/A 7.5 HIGH
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.
CVE-2025-60662 1 Tenda 2 Ac18, Ac18 Firmware 2025-10-07 N/A 7.5 HIGH
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.