Vulnerabilities > Tenda

DATE CVE VULNERABILITY TITLE RISK
2022-11-15 CVE-2022-40846 Cross-site Scripting vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.
network
low complexity
tenda CWE-79
4.8
2022-11-15 CVE-2022-41395 OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.
local
low complexity
tenda CWE-78
7.8
2022-11-15 CVE-2022-41396 OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.
local
low complexity
tenda CWE-78
7.8
2022-11-15 CVE-2022-42053 OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.
local
low complexity
tenda CWE-78
7.8
2022-11-15 CVE-2022-42058 Out-of-bounds Write vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function.
network
low complexity
tenda CWE-787
critical
9.8
2022-11-15 CVE-2022-42060 Out-of-bounds Write vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function.
network
low complexity
tenda CWE-787
7.5
2022-11-15 CVE-2022-40843 Unspecified vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed.
network
low complexity
tenda
4.9
2022-11-15 CVE-2022-40845 Forced Browsing vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability.
network
low complexity
tenda CWE-425
6.5
2022-11-15 CVE-2022-40847 OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools.
local
low complexity
tenda CWE-78
7.8
2022-11-03 CVE-2022-43101 Out-of-bounds Write vulnerability in Tenda Ac23 Firmware 16.03.07.45Cn
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
network
low complexity
tenda CWE-787
critical
9.8