Vulnerabilities (CVE)

Filtered by vendor Tenda Subscribe
Total 609 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37717 1 Tenda 14 Ac10, Ac10 Firmware, Ac1206 and 11 more 2024-02-05 N/A 9.8 CRITICAL
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient.
CVE-2023-38930 1 Tenda 10 Ac5, Ac5 Firmware, Ac7 and 7 more 2024-02-05 N/A 9.8 CRITICAL
Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
CVE-2023-37722 1 Tenda 6 4g300, 4g300 Firmware, F1202 and 3 more 2024-02-05 N/A 9.8 CRITICAL
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeUrlFilter.
CVE-2023-38929 1 Tenda 2 4g300, 4g300 Firmware 2024-02-05 N/A 9.8 CRITICAL
Tenda 4G300 v1.01.42 was discovered to contain a stack overflow via the page parameter at /VirtualSer.
CVE-2023-38940 1 Tenda 6 F1203, F1203 Firmware, Fh1203 and 3 more 2024-02-05 N/A 9.8 CRITICAL
Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
CVE-2023-37721 1 Tenda 10 4g300, 4g300 Firmware, F1202 and 7 more 2024-02-05 N/A 9.8 CRITICAL
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeMacFilter.
CVE-2023-39827 1 Tenda 2 A18, A18 Firmware 2024-02-05 N/A 7.5 HIGH
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.
CVE-2023-38932 1 Tenda 8 F1202, F1202 Firmware, Fh1202 and 5 more 2024-02-05 N/A 9.8 CRITICAL
Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter in the SafeEmailFilter function.
CVE-2023-37719 1 Tenda 8 F1202, F1202 Firmware, Fh1202 and 5 more 2024-02-05 N/A 9.8 CRITICAL
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromP2pListFilter.
CVE-2023-30370 1 Tenda 2 Ac15, Ac15 Firmware 2024-02-04 N/A 9.8 CRITICAL
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.
CVE-2023-33672 1 Tenda 2 Ac8, Ac8 Firmware 2024-02-04 N/A 7.5 HIGH
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.
CVE-2023-37144 2 Tenda, Tendacn 2 Ac10, Ac10 Firmware 2024-02-04 N/A 9.8 CRITICAL
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
CVE-2023-30352 1 Tenda 2 Cp3, Cp3 Firmware 2024-02-04 N/A 9.8 CRITICAL
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
CVE-2023-37710 1 Tenda 4 Ac10, Ac10 Firmware, Ac1206 and 1 more 2024-02-04 N/A 9.8 CRITICAL
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
CVE-2023-37707 1 Tenda 2 Fh1203, Fh1203 Firmware 2024-02-04 N/A 9.8 CRITICAL
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.
CVE-2023-30354 1 Tenda 2 Cp3, Cp3 Firmware 2024-02-04 N/A 9.8 CRITICAL
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
CVE-2023-33530 1 Tenda 2 G103, G103 Firmware 2024-02-04 N/A 8.8 HIGH
There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.
CVE-2023-33671 1 Tenda 2 Ac8, Ac8 Firmware 2024-02-04 N/A 9.8 CRITICAL
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.
CVE-2023-29681 1 Tenda 2 N301, N301 Firmware 2024-02-04 N/A 5.7 MEDIUM
Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.
CVE-2023-30135 1 Tenda 2 Ac18, Ac18 Firmware 2024-02-04 N/A 9.8 CRITICAL
Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.