Vulnerabilities > Tenda > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-06-02 CVE-2023-33670 Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function.
network
low complexity
tenda CWE-787
critical
9.8
2023-06-02 CVE-2023-33671 Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.
network
low complexity
tenda CWE-787
critical
9.8
2023-06-02 CVE-2023-33673 Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
network
low complexity
tenda CWE-787
critical
9.8
2023-06-02 CVE-2023-33675 Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_list_Info function.
network
low complexity
tenda CWE-787
critical
9.8
2023-05-27 CVE-2023-2923 Out-of-bounds Write vulnerability in Tenda AC6 Firmware Usac6V1.0Brv15.03.05.19
A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19.
network
low complexity
tenda CWE-787
critical
9.8
2023-05-16 CVE-2023-31587 Unspecified vulnerability in Tenda AC5 Firmware 15.03.06.28
Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.
network
low complexity
tenda
critical
9.8
2023-05-10 CVE-2023-30352 Use of Hard-coded Credentials vulnerability in Tenda CP3 Firmware 11.10.00.2211041355
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
network
low complexity
tenda CWE-798
critical
9.8
2023-05-10 CVE-2023-30353 Command Injection vulnerability in Tenda CP3 Firmware 11.10.00.2211041355
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.
network
low complexity
tenda CWE-77
critical
9.8
2023-05-10 CVE-2023-30354 Cleartext Transmission of Sensitive Information vulnerability in Tenda CP3 Firmware 11.10.00.2211041355
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
network
low complexity
tenda CWE-319
critical
9.8
2023-05-05 CVE-2023-30135 Command Injection vulnerability in Tenda Ac18 Firmware 15.03.05.19(6318)Cn
Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.
network
low complexity
tenda CWE-77
critical
9.8