Vulnerabilities > Tendacn
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-04 | CVE-2022-24170 | Command Injection vulnerability in Tendacn G1 Firmware and G3 Firmware Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. | 7.5 |
2022-02-04 | CVE-2022-24171 | Command Injection vulnerability in Tendacn G1 Firmware and G3 Firmware Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. | 7.5 |
2022-02-04 | CVE-2022-24172 | Out-of-bounds Write vulnerability in Tendacn G1 Firmware and G3 Firmware Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBindRule. | 7.8 |
2021-12-03 | CVE-2021-44352 | Out-of-bounds Write vulnerability in Tendacn Ac15 Firmware 15.03.05.18Multi A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind. | 7.5 |
2021-10-29 | CVE-2020-22079 | Out-of-bounds Write vulnerability in Tendacn Ac10U Firmware and AC9 Firmware Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg. | 9.8 |
2021-10-29 | CVE-2021-31624 | Classic Buffer Overflow vulnerability in Tendacn AC9 Firmware 15.03.05.14En/15.03.05.19 Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the urls parameter. | 5.8 |
2021-10-29 | CVE-2021-31627 | Classic Buffer Overflow vulnerability in Tendacn AC9 Firmware 15.03.05.14En/15.03.05.19 Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the index parameter. | 5.8 |
2021-09-30 | CVE-2020-20746 | Out-of-bounds Write vulnerability in Tendacn AC9 Firmware 15.03.06.60En A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg. | 6.5 |
2021-04-16 | CVE-2021-27692 | OS Command Injection vulnerability in Tendacn G1 Firmware and G3 Firmware Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted "action/umountUSBPartition" request. | 9.8 |
2021-04-16 | CVE-2021-27691 | OS Command Injection vulnerability in Tendacn G0 Firmware, G1 Firmware and G3 Firmware Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. | 9.8 |