Vulnerabilities > Tenda

DATE CVE VULNERABILITY TITLE RISK
2021-01-01 CVE-2020-35391 Forced Browsing vulnerability in Tenda F3 Firmware 12.01.01.48
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942.
low complexity
tenda CWE-425
6.5
2020-12-30 CVE-2020-28095 Infinite Loop vulnerability in Tenda Ac1200 Firmware 15.03.06.51Multi
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
network
low complexity
tenda CWE-835
7.5
2020-07-23 CVE-2020-15916 OS Command Injection vulnerability in Tenda Ac15 Firmware 15.03.05.19
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
network
low complexity
tenda CWE-78
critical
9.8
2020-07-13 CVE-2020-10989 Cross-site Scripting vulnerability in Tenda Ac15 Firmware 15.03.05.19
An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.
network
low complexity
tenda CWE-79
6.1
2020-07-13 CVE-2020-10988 Use of Hard-coded Credentials vulnerability in Tenda Ac15 Firmware 15.03.05.19
A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.
network
low complexity
tenda CWE-798
critical
9.8
2020-07-13 CVE-2020-10987 OS Command Injection vulnerability in Tenda Ac15 Firmware 15.03.05.19
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
network
low complexity
tenda CWE-78
critical
9.8
2020-07-13 CVE-2020-10986 Cross-Site Request Forgery (CSRF) vulnerability in Tenda Ac15 Firmware 15.03.05.19
A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.
network
low complexity
tenda CWE-352
6.5
2019-09-13 CVE-2019-16288 Unspecified vulnerability in Tenda N301 Firmware
On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the device to crash.
network
low complexity
tenda
7.5
2019-04-25 CVE-2018-14559 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tenda Ac10 Firmware, AC7 Firmware and AC9 Firmware
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10).
network
low complexity
tenda CWE-119
7.5
2019-04-25 CVE-2018-14557 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tenda Ac10 Firmware, AC7 Firmware and AC9 Firmware
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10).
network
low complexity
tenda CWE-119
7.5