Vulnerabilities (CVE)

Filtered by vendor Tenda Subscribe
Total 626 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-34942 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 N/A 8.8 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.
CVE-2024-34944 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 N/A 8.8 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.
CVE-2024-44386 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 N/A 7.3 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.
CVE-2025-29121 1 Tenda 2 Ac6, Ac6 Firmware 2025-03-28 N/A 7.5 HIGH
A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.
CVE-2024-46429 1 Tenda 2 W18e, W18e Firmware 2025-03-28 N/A 8.8 HIGH
A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.
CVE-2025-29149 1 Tenda 2 I12, I12 Firmware 2025-03-27 N/A 7.5 HIGH
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.
CVE-2024-46434 1 Tenda 2 W18e, W18e Firmware 2025-03-25 N/A 8.8 HIGH
Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP request.
CVE-2024-46433 1 Tenda 2 W18e, W18e Firmware 2025-03-25 N/A 8.8 HIGH
A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges.
CVE-2024-46432 1 Tenda 2 W18e, W18e Firmware 2025-03-25 N/A 8.8 HIGH
Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized changes to WiFi configuration settings and administrative credentials.
CVE-2024-46431 1 Tenda 2 W18e, W18e Firmware 2025-03-25 N/A 8.0 HIGH
Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted data to the delWewifiPic function.
CVE-2024-46435 1 Tenda 2 W18e, W18e Firmware 2025-03-25 N/A 8.0 HIGH
A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. This vulnerability occurs due to improper input validation when handling user-supplied data in the delFacebookPic function.
CVE-2024-46436 1 Tenda 2 W18e, W18e Firmware 2025-03-25 N/A 8.3 HIGH
Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.
CVE-2025-29214 1 Tenda 2 Ax12, Ax12 Firmware 2025-03-25 N/A 7.5 HIGH
Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.
CVE-2025-29101 1 Tenda 2 Ac8, Ac8 Firmware 2025-03-25 N/A 7.5 HIGH
Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function.
CVE-2023-24332 1 Tenda 2 Ac6, Ac6 Firmware 2025-03-25 N/A 8.1 HIGH
A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.
CVE-2023-24333 1 Tenda 2 Ac21, Ac21 Firmware 2025-03-25 N/A 8.8 HIGH
A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/openSchedWifi.
CVE-2023-24334 1 Tenda 2 Ac23, Ac23 Firmware 2025-03-25 N/A 8.0 HIGH
A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.
CVE-2025-0349 1 Tenda 2 Ac6, Ac6 Firmware 2025-03-22 9.0 HIGH 8.8 HIGH
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src/mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVE-2024-42952 1 Tenda 2 Fh1201, Fh1201 Firmware 2025-03-18 N/A 7.5 HIGH
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2025-29387 1 Tenda 2 Ac9, Ac9 Firmware 2025-03-17 N/A 7.1 HIGH
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.