Vulnerabilities > Tendacn > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-24488 Cleartext Storage of Sensitive Information vulnerability in Tendacn CP3 Firmware 11.10.00.2311090948
An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.
local
low complexity
tendacn CWE-312
5.5
2022-07-01 CVE-2022-32384 Out-of-bounds Write vulnerability in Tendacn Ac23 Ac2100 Firmware 16.03.07.44
Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWifiBasicSet.
low complexity
tendacn CWE-787
5.8
2021-10-29 CVE-2021-31624 Classic Buffer Overflow vulnerability in Tendacn AC9 Firmware 15.03.05.14En/15.03.05.19
Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the urls parameter.
low complexity
tendacn CWE-120
5.8
2021-10-29 CVE-2021-31627 Classic Buffer Overflow vulnerability in Tendacn AC9 Firmware 15.03.05.14En/15.03.05.19
Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the index parameter.
low complexity
tendacn CWE-120
5.8
2021-09-30 CVE-2020-20746 Out-of-bounds Write vulnerability in Tendacn AC9 Firmware 15.03.06.60En
A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.
network
low complexity
tendacn CWE-787
6.5
2020-12-28 CVE-2020-28094 Unspecified vulnerability in Tendacn Ac1200 Firmware 15.03.06.51
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to download malware named elive or CNKI E-Learning.
network
low complexity
tendacn
5.0
2020-12-28 CVE-2020-28093 Unspecified vulnerability in Tendacn Ac1200 Firmware 15.03.06.51
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.
network
low complexity
tendacn
6.5
2019-11-21 CVE-2019-5072 OS Command Injection vulnerability in Tendacn Ac9V1.0 Firmware 15.03.05.14En/15.03.05.16Multitru
An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU).
local
low complexity
tendacn CWE-78
4.6
2018-07-21 CVE-2018-14492 Out-of-bounds Write vulnerability in Tendacn products
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
network
low complexity
tendacn CWE-787
5.0