Vulnerabilities > Tenda

DATE CVE VULNERABILITY TITLE RISK
2023-11-20 CVE-2023-48109 Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentControlInfo .
network
low complexity
tenda CWE-787
7.5
2023-11-20 CVE-2023-48110 Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControlInfo .
network
low complexity
tenda CWE-787
7.5
2023-11-20 CVE-2023-48111 Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo .
network
low complexity
tenda CWE-787
7.5
2023-11-14 CVE-2022-45781 Out-of-bounds Write vulnerability in Tenda Ax1803 Firmware 1.0.0.1/1.0.0.12890
Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /goform/SetOnlineDevName.
network
low complexity
tenda CWE-787
8.8
2023-11-07 CVE-2023-47455 Out-of-bounds Write vulnerability in Tenda Ax1806 Firmware 1.0.0.1
Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.
network
low complexity
tenda CWE-787
critical
9.1
2023-11-07 CVE-2023-47456 Out-of-bounds Write vulnerability in Tenda Ax1806 Firmware 1.0.0.1
Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat.
network
low complexity
tenda CWE-787
critical
9.1
2023-11-07 CVE-2023-43885 Missing Authorization vulnerability in Tenda RX9 PRO Firmware 22.03.02.10
Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.
network
low complexity
tenda CWE-862
8.1
2023-11-07 CVE-2023-43886 Out-of-bounds Write vulnerability in Tenda RX9 PRO Firmware 22.03.02.10
A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to overwrite memory.
network
low complexity
tenda CWE-787
7.1
2023-10-25 CVE-2023-46369 Out-of-bounds Write vulnerability in Tenda W18E Firmware 16.01.0.8(1576)
Tenda W18E V16.01.0.8(1576) contains a stack overflow vulnerability via the portMirrorMirroredPorts parameter in the formSetNetCheckTools function.
network
low complexity
tenda CWE-787
critical
9.8
2023-10-25 CVE-2023-46370 Command Injection vulnerability in Tenda W18E Firmware 16.01.0.8(1576)
Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.
network
low complexity
tenda CWE-77
critical
9.8