Vulnerabilities > Tenda > Ax1803 Firmware > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-10 | CVE-2023-51961 | Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1 Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv. | 9.8 |
2024-01-10 | CVE-2023-51972 | Command Injection vulnerability in Tenda Ax1803 Firmware 1.0.0.1 Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp. | 9.8 |
2024-01-10 | CVE-2023-51971 | Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1 Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo. | 9.8 |
2023-11-27 | CVE-2023-49044 | Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1 Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set. | 9.8 |
2023-11-27 | CVE-2023-49042 | Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1 Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi. | 9.8 |
2023-11-27 | CVE-2023-49040 | Command Injection vulnerability in Tenda Ax1803 Firmware 1.0.0.1 An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function. | 9.8 |
2023-11-27 | CVE-2023-49046 | Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1 Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule. | 9.8 |
2023-11-27 | CVE-2023-49043 | Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1 Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat. | 9.8 |
2022-10-27 | CVE-2022-40876 | Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1 In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE). | 9.8 |
2022-07-06 | CVE-2022-34596 | OS Command Injection vulnerability in Tenda Ax1803 Firmware 1.0.0.12890 Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting. | 9.8 |