Total
56 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-2807 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-05-17 | 9.0 HIGH | 9.8 CRITICAL |
A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi. This vulnerability affects the function formExpandDlnaFile of the file /goform/expandDlnaFile. The manipulation of the argument filePath leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257662 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
CVE-2024-2806 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-05-17 | 9.0 HIGH | 9.8 CRITICAL |
A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This affects the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the argument deviceId/deviceMac leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257661 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
CVE-2023-39673 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34(). | |||||
CVE-2023-30376 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability. | |||||
CVE-2023-30370 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability. | |||||
CVE-2023-30372 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability. | |||||
CVE-2023-30375 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability. | |||||
CVE-2023-30369 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow. | |||||
CVE-2023-30373 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability. | |||||
CVE-2023-30378 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability. | |||||
CVE-2023-30371 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability. | |||||
CVE-2022-44168 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 7.5 HIGH |
Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function fromSetRouteStatic.. | |||||
CVE-2022-44167 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 7.5 HIGH |
Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer. | |||||
CVE-2022-44169 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 7.5 HIGH |
Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function formSetVirtualSer. | |||||
CVE-2022-44156 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 7.5 HIGH |
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind. | |||||
CVE-2022-37175 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet. | |||||
CVE-2022-43259 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 7.5 HIGH |
Tenda AC15 V15.03.05.18 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function. | |||||
CVE-2022-40851 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | N/A | 9.8 CRITICAL |
Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat. | |||||
CVE-2022-28556 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in stack overflow. Similarly, this vulnerability can be used together with CVE-2021-44971 | |||||
CVE-2022-28557 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution |