Vulnerabilities (CVE)

Filtered by vendor Tenda Subscribe
Total 1166 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45503 1 Tenda 2 W6-s, W6-s Firmware 2025-04-23 N/A 7.5 HIGH
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the linkEn parameter at /goform/setAutoPing.
CVE-2022-45501 1 Tenda 2 W6-s, W6-s Firmware 2025-04-23 N/A 7.5 HIGH
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.
CVE-2022-45499 1 Tenda 2 W6-s, W6-s Firmware 2025-04-23 N/A 7.5 HIGH
Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.
CVE-2022-45498 1 Tenda 2 W6-s, W6-s Firmware 2025-04-23 N/A 7.5 HIGH
An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.
CVE-2022-45497 1 Tenda 2 W6-s, W6-s Firmware 2025-04-23 N/A 9.8 CRITICAL
Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.
CVE-2022-45043 1 Tenda 2 Ax12, Ax12 Firmware 2025-04-22 N/A 8.8 HIGH
Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.
CVE-2022-45997 1 Tenda 2 W15e, W20e Firmware 2025-04-22 N/A 7.2 HIGH
Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.
CVE-2022-45996 1 Tenda 2 W15e, W20e Firmware 2025-04-22 N/A 7.2 HIGH
Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
CVE-2022-45980 1 Tenda 2 Ax12, Ax12 Firmware 2025-04-22 N/A 8.8 HIGH
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
CVE-2022-45979 1 Tenda 2 Ax12, Ax12 Firmware 2025-04-22 N/A 7.5 HIGH
Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .
CVE-2022-45977 1 Tenda 2 Ax12, Ax12 Firmware 2025-04-22 N/A 8.8 HIGH
Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.
CVE-2025-25457 1 Tenda 2 Ac10, Ac10 Firmware 2025-04-22 N/A 7.5 HIGH
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.
CVE-2025-25453 1 Tenda 2 Ac10, Ac10 Firmware 2025-04-22 N/A 4.6 MEDIUM
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
CVE-2025-25458 1 Tenda 2 Ac10, Ac10 Firmware 2025-04-22 N/A 4.6 MEDIUM
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
CVE-2025-25456 1 Tenda 2 Ac10, Ac10 Firmware 2025-04-22 N/A 9.8 CRITICAL
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
CVE-2025-25454 1 Tenda 2 Ac10, Ac10 Firmware 2025-04-22 N/A 7.5 HIGH
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
CVE-2025-25455 1 Tenda 2 Ac10, Ac10 Firmware 2025-04-22 N/A 7.5 HIGH
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
CVE-2025-3786 1 Tenda 2 Ac15, Ac15 Firmware 2025-04-22 9.0 HIGH 8.8 HIGH
A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument mac leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-29462 1 Tenda 2 Ac15, Ac15 Firmware 2025-04-22 N/A 9.8 CRITICAL
A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.
CVE-2017-14515 1 Tenda 2 W15e, W15e Firmware 2025-04-20 5.0 MEDIUM 7.5 HIGH
Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service (temporary HTTP outage and forced logout) via unspecified vectors.