Vulnerabilities > Tenda > W15E Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2024-04-24 CVE-2024-4115 Out-of-bounds Write vulnerability in Tenda W15E Firmware 15.11.0.14
A vulnerability, which was classified as critical, was found in Tenda W15E 15.11.0.14.
network
low complexity
tenda CWE-787
8.8
2024-04-24 CVE-2024-4116 Out-of-bounds Write vulnerability in Tenda W15E Firmware 15.11.0.14
A vulnerability has been found in Tenda W15E 15.11.0.14 and classified as critical.
network
low complexity
tenda CWE-787
8.8
2024-04-24 CVE-2024-4117 Out-of-bounds Write vulnerability in Tenda W15E Firmware 15.11.0.14
A vulnerability was found in Tenda W15E 15.11.0.14 and classified as critical.
network
low complexity
tenda CWE-787
8.8
2023-03-13 CVE-2023-27062 Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14
Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function.
network
low complexity
tenda CWE-120
7.5
2023-03-13 CVE-2023-27064 Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function.
network
low complexity
tenda CWE-120
7.5
2023-03-13 CVE-2023-27065 Classic Buffer Overflow vulnerability in Tenda W15E Firmware 15.11.0.14
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function.
network
low complexity
tenda CWE-120
7.5
2022-11-15 CVE-2022-41395 OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.
local
low complexity
tenda CWE-78
7.8
2022-11-15 CVE-2022-41396 OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.
local
low complexity
tenda CWE-78
7.8
2022-11-15 CVE-2022-42053 OS Command Injection vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.
local
low complexity
tenda CWE-78
7.8
2022-11-15 CVE-2022-42060 Out-of-bounds Write vulnerability in Tenda W15E Firmware 15.11.0.10(1576)
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function.
network
low complexity
tenda CWE-787
7.5