Vulnerabilities > Tenda > W15E Firmware > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-03-13 | CVE-2023-27062 | Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14 Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. | 7.5 |
2023-03-13 | CVE-2023-27064 | Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14 Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. | 7.5 |
2023-03-13 | CVE-2023-27065 | Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14 Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. | 7.5 |
2022-11-15 | CVE-2022-41395 | OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576) Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function. | 7.8 |
2022-11-15 | CVE-2022-41396 | OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576) Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters. | 7.8 |
2022-11-15 | CVE-2022-42053 | OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576) Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function. | 7.8 |
2022-11-15 | CVE-2022-42060 | Out-of-bounds Write vulnerability in Tenda W15E Firmware 15.11.0.10(1576) Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. | 7.5 |
2022-11-15 | CVE-2022-40847 | OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576) In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. | 7.8 |
2017-09-17 | CVE-2017-14515 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tenda W15E Firmware 15.11.0.10(1576)/15.11.0.14/V15.11.0.13Cn Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service (temporary HTTP outage and forced logout) via unspecified vectors. | 7.5 |
2017-09-17 | CVE-2017-14514 | Path Traversal vulnerability in Tenda W15E Firmware 15.11.0.10(1576)/15.11.0.14/V15.11.0.13Cn Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a crafted URL. | 7.5 |