Vulnerabilities > Tenda > Ac1200 Firmware

DATE CVE VULNERABILITY TITLE RISK
2021-01-26 CVE-2021-3186 Cross-site Scripting vulnerability in Tenda Ac1200 Firmware 15.03.06.47Multi
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter.
network
tenda CWE-79
4.3
2020-12-30 CVE-2020-28095 Infinite Loop vulnerability in Tenda Ac1200 Firmware 15.03.06.51Multi
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
network
low complexity
tenda CWE-835
7.8