Filtered by vendor Tenda
Subscriptions
Total
863 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-26728 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2024-08-04 | 9.8 Critical |
A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request. | ||||
CVE-2020-15916 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-08-04 | 9.8 Critical |
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter. | ||||
CVE-2020-10989 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-08-04 | 6.1 Medium |
An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter. | ||||
CVE-2020-10986 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-08-04 | 6.5 Medium |
A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page. | ||||
CVE-2020-10988 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-08-04 | 9.8 Critical |
A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device. | ||||
CVE-2020-10987 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-08-04 | 9.8 Critical |
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter. | ||||
CVE-2021-46408 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2024-08-04 | 7.5 High |
Tenda AX12 v22.03.01.21 was discovered to contain a stack buffer overflow in the function sub_422CE4. This vulnerability allows attackers to cause a Denial of Service (DoS) via the strcpy parameter. | ||||
CVE-2021-46393 | 1 Tenda | 2 Ax3, Ax3 Firmware | 2024-08-04 | 9.8 Critical |
There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security check,which causes stack overflow. By POSTing the page /goform/SetPptpServerCfg with proper startIp, the attacker can easily perform remote code execution with carefully crafted overflow data. | ||||
CVE-2021-46394 | 1 Tenda | 2 Ax3, Ax3 Firmware | 2024-08-04 | 9.8 Critical |
There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check, which causes stack overflow. By POSTing the page /goform/SetPptpServerCfg with proper startIp, the attacker can easily perform remote code execution with carefully crafted overflow data. | ||||
CVE-2021-46264 | 1 Tenda | 2 Ac11, Ac11 Firmware | 2024-08-04 | 9.8 Critical |
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the onlineList module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data. | ||||
CVE-2021-46263 | 1 Tenda | 2 Ac11, Ac11 Firmware | 2024-08-04 | 9.8 Critical |
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiTime module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data. | ||||
CVE-2021-46262 | 1 Tenda | 2 Ac11, Ac11 Firmware | 2024-08-04 | 9.8 Critical |
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data. | ||||
CVE-2021-46321 | 1 Tenda | 2 Ac11, Ac11 Firmware | 2024-08-04 | 9.8 Critical |
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiBasicCfg module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data. | ||||
CVE-2021-46265 | 1 Tenda | 2 Ac11, Ac11 Firmware | 2024-08-04 | 9.8 Critical |
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wanBasicCfg module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data. | ||||
CVE-2021-45392 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2024-08-04 | 7.5 High |
A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service. | ||||
CVE-2021-45391 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2024-08-04 | 7.5 High |
A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/setIPv6Status binary file /usr/sbin/httpd via the conType parameter, which causes a Denial of Service. | ||||
CVE-2021-44971 | 1 Tenda | 4 Ac15, Ac15 Firmware, Ac5 and 1 more | 2024-08-04 | 9.8 Critical |
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE. | ||||
CVE-2021-42659 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2024-08-04 | 6.5 Medium |
There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long list parameter occurs. | ||||
CVE-2021-40546 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2024-08-04 | 4.9 Medium |
Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi. | ||||
CVE-2021-31755 | 1 Tenda | 2 Ac11, Ac11 Firmware | 2024-08-03 | 9.8 Critical |
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request. |