Vulnerabilities > Tenda

DATE CVE VULNERABILITY TITLE RISK
2023-04-04 CVE-2023-26976 Out-of-bounds Write vulnerability in Tenda AC6 Firmware 15.03.05.09
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
network
low complexity
tenda CWE-787
7.5
2023-03-24 CVE-2023-27042 Out-of-bounds Write vulnerability in Tenda AX3 Firmware 16.03.12.11
Tenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg.
network
low complexity
tenda CWE-787
8.8
2023-03-23 CVE-2023-27079 Command Injection vulnerability in Tenda G103 Firmware 1.0.05
Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package
network
low complexity
tenda CWE-77
7.5
2023-03-19 CVE-2023-26805 Out-of-bounds Write vulnerability in Tenda W20E Firmware 15.11.0.6
Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.
network
low complexity
tenda CWE-787
critical
9.8
2023-03-19 CVE-2023-26806 Out-of-bounds Write vulnerability in Tenda W20E Firmware 15.11.0.6
Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,
network
low complexity
tenda CWE-787
critical
9.8
2023-03-15 CVE-2023-27239 Out-of-bounds Write vulnerability in Tenda AX3 Firmware 16.03.12.11
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet.
network
low complexity
tenda CWE-787
critical
9.8
2023-03-15 CVE-2023-27240 Command Injection vulnerability in Tenda AX3 Firmware 16.03.12.11
Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.
network
low complexity
tenda CWE-77
critical
9.8
2023-03-13 CVE-2023-27061 Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function.
network
low complexity
tenda CWE-120
critical
9.8
2023-03-13 CVE-2023-27062 Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14
Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function.
network
low complexity
tenda CWE-120
7.5
2023-03-13 CVE-2023-27063 Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function.
network
low complexity
tenda CWE-120
critical
9.8