Vulnerabilities (CVE)

Filtered by vendor Tenda Subscribe
Total 802 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37706 1 Tenda 2 Fh1203, Fh1203 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.
CVE-2023-30369 1 Tenda 2 Ac15, Ac15 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.
CVE-2023-25219 1 Tenda 2 Ac5, Ac5 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
CVE-2023-27012 1 Tenda 2 Ac10, Ac10 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
CVE-2023-25215 1 Tenda 2 Ac5, Ac5 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
CVE-2023-30352 1 Tenda 2 Cp3, Cp3 Firmware 2024-02-28 N/A 9.8 CRITICAL
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
CVE-2023-33672 1 Tenda 2 Ac8, Ac8 Firmware 2024-02-28 N/A 7.5 HIGH
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.
CVE-2023-27019 1 Tenda 2 Ac10, Ac10 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
CVE-2023-25214 1 Tenda 2 Ac5, Ac5 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
CVE-2023-26976 1 Tenda 2 Ac6, Ac6 Firmware 2024-02-28 N/A 7.5 HIGH
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
CVE-2023-30373 1 Tenda 2 Ac15, Ac15 Firmware 2024-02-28 N/A 9.8 CRITICAL
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.
CVE-2023-34566 1 Tenda 2 Ac10, Ac10 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.
CVE-2023-30351 1 Tenda 2 Cp3, Cp3 Firmware 2024-02-28 N/A 7.5 HIGH
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.
CVE-2023-33673 1 Tenda 2 Ac8, Ac8 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
CVE-2023-30135 1 Tenda 2 Ac18, Ac18 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.
CVE-2023-33530 1 Tenda 2 G103, G103 Firmware 2024-02-28 N/A 8.8 HIGH
There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.
CVE-2023-27018 1 Tenda 2 Ac10, Ac10 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
CVE-2023-30368 1 Tenda 2 Ac5, Ac5 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.
CVE-2023-34568 1 Tenda 2 Ac10, Ac10 Firmware 2024-02-28 N/A 6.7 MEDIUM
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.
CVE-2023-33670 1 Tenda 2 Ac8, Ac8 Firmware 2024-02-28 N/A 9.8 CRITICAL
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function.