Tenda A18 Pro vulnerabilities

5 known vulnerabilities affecting tenda/a18_pro.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5

Vulnerabilities

Page 1 of 1
CVE-2026-4490HIGHCVSS 7.4v02.03.02.282026-03-20
CVE-2026-4490 [HIGH] CWE-119 CVE-2026-4490: A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
cvelistv5nvd
CVE-2026-4493HIGHCVSS 7.4v02.03.02.282026-03-20
CVE-2026-4493 [HIGH] CWE-119 CVE-2026-4493: A vulnerability was determined in Tenda A18 Pro 02.03.02.28. The impacted element is the function su A vulnerability was determined in Tenda A18 Pro 02.03.02.28. The impacted element is the function sub_423B50 of the file /goform/setMacFilterCfg of the component MAC Filtering Configuration Endpoint. Executing a manipulation of the argument deviceList can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been
cvelistv5nvd
CVE-2026-4491HIGHCVSS 7.4v02.03.02.282026-03-20
CVE-2026-4491 [HIGH] CWE-119 CVE-2026-4491: A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBi A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument list leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2026-4489HIGHCVSS 7.4v02.03.02.282026-03-20
CVE-2026-4489 [HIGH] CWE-119 CVE-2026-4489: A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function f A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
cvelistv5nvd
CVE-2026-4492HIGHCVSS 7.4v02.03.02.282026-03-20
CVE-2026-4492 [HIGH] CWE-119 CVE-2026-4492: A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qos A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
cvelistv5nvd