Vulnerabilities > Tendacn > PA6 > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-06-25 CVE-2019-16213 OS Command Injection vulnerability in Tendacn PA6 Firmware 1.0.1.21
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system.
tendacn CWE-78
critical
9.0
2020-06-25 CVE-2019-19505 Out-of-bounds Write vulnerability in Tendacn PA6 Firmware 1.0.1.21
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI.
tendacn CWE-787
critical
9.0