Filtered by vendor Tenda
Subscribe
Total
800 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-28572 | 1 Tenda | 4 Ax1803, Ax1803 Firmware, Ax1806 and 1 more | 2024-02-28 | 6.5 MEDIUM | 8.8 HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function | |||||
CVE-2022-25446 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function. | |||||
CVE-2022-25450 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function. | |||||
CVE-2022-27079 | 1 Tenda | 2 M3, M3 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem. | |||||
CVE-2022-28557 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution | |||||
CVE-2022-25555 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2024-02-28 | 7.8 HIGH | 7.5 HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ntpServer parameter. | |||||
CVE-2022-25429 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo function. | |||||
CVE-2022-25451 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function. | |||||
CVE-2022-25546 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2024-02-28 | 7.8 HIGH | 7.5 HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsUser parameter. | |||||
CVE-2022-25554 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2024-02-28 | 7.8 HIGH | 7.5 HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceId parameter. | |||||
CVE-2022-27077 | 1 Tenda | 2 M3, M3 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic. | |||||
CVE-2022-25548 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2024-02-28 | 7.8 HIGH | 7.5 HIGH |
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the serverName parameter. | |||||
CVE-2022-25459 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function. | |||||
CVE-2022-25447 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function. | |||||
CVE-2022-30474 | 1 Tenda | 2 Ac18, Ac18 Firmware | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request. | |||||
CVE-2022-25453 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function. | |||||
CVE-2021-46394 | 1 Tenda | 2 Ax3, Ax3 Firmware | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check, which causes stack overflow. By POSTing the page /goform/SetPptpServerCfg with proper startIp, the attacker can easily perform remote code execution with carefully crafted overflow data. | |||||
CVE-2022-27374 | 1 Tenda | 2 Ax12, Ax12 Firmware | 2024-02-28 | 7.1 HIGH | 6.5 MEDIUM |
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot. | |||||
CVE-2022-27022 | 1 Tenda | 2 Ac9, Ac9 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload. | |||||
CVE-2022-25457 | 1 Tenda | 2 Ac6, Ac6 Firmware | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function. |