Tenda Ac10 Firmware vulnerabilities
92 known vulnerabilities affecting tenda/ac10_firmware.
Total CVEs
92
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL47HIGH31MEDIUM14
Vulnerabilities
Page 3 of 5
CVE-2025-67073P3CRITICALCVSS 9.8v16.03.10.202025-12-17
CVE-2025-67073 [CRITICAL] CWE-120 CVE-2025-67073: A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.0
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.
nvd
CVE-2023-38935P3CRITICALCVSS 9.8v16.03.10.132023-08-07
CVE-2023-38935 [CRITICAL] CWE-787 CVE-2023-38935: Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC
Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.
nvd
CVE-2023-27012P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27012 [CRITICAL] CWE-787 CVE-2023-27012: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSched
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-27014P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27014 [CRITICAL] CWE-787 CVE-2023-27014: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC38 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-27016P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27016 [CRITICAL] CWE-787 CVE-2023-27016: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSe
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-27015P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27015 [CRITICAL] CWE-787 CVE-2023-27015: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75C0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-27019P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27019 [CRITICAL] CWE-787 CVE-2023-27019: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458F
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-27021P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27021 [CRITICAL] CWE-787 CVE-2023-27021: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetF
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-27020P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27020 [CRITICAL] CWE-787 CVE-2023-27020: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the savePare
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-27017P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27017 [CRITICAL] CWE-787 CVE-2023-27017: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-27018P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27018 [CRITICAL] CWE-787 CVE-2023-27018: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-27013P3CRITICALCVSS 9.8v16.03.10.13_cn2023-04-07
CVE-2023-27013 [CRITICAL] CWE-787 CVE-2023-27013: Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_pare
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-37716P3CRITICALCVSS 9.8v1.02023-07-14
CVE-2023-37716 [CRITICAL] CWE-787 CVE-2023-37716: Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting.
nvd
CVE-2023-37717P3CRITICALCVSS 9.8v1.02023-07-14
CVE-2023-37717 [CRITICAL] CWE-787 CVE-2023-37717: Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient.
nvd
CVE-2025-25456P3CRITICALCVSS 9.8v16.03.10.202025-04-15
CVE-2025-25456 [CRITICAL] CWE-120 CVE-2025-25456: Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
nvd
CVE-2018-18729P3CRITICALCVSS 9.8v15.03.06.23_cn2018-10-29
CVE-2018-18729 [CRITICAL] CWE-787 CVE-2018-18729: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy
nvd
CVE-2023-42320P3CRITICALCVSS 9.8v16.03.10.132023-09-18
CVE-2023-42320 [CRITICAL] CWE-120 CVE-2023-42320: Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote
Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.
nvd
CVE-2026-5549P3HIGHCVSS 7.5v16.03.10.10_multi_tde012026-04-05
CVE-2026-5549 [HIGH] CWE-320 CVE-2026-5549: A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some
A vulnerability was determined in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this issue is some unknown functionality of the file /webroot_ro/pem/privkeySrv.pem of the component RSA 2048-bit Private Key Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack can be launched remotely. The exploit has been publi
nvd
CVE-2025-4896P3HIGHCVSS 7.5v16.03.10.132025-05-18
CVE-2025-4896 [HIGH] CWE-119 CVE-2025-4896: A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this iss
A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/UserCongratulationsExec. The manipulation of the argument getuid leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-32317P3HIGHCVSS 7.5v16.03.10.13v16.03.10.202024-04-17
CVE-2024-32317 [HIGH] CWE-121 CVE-2024-32317: Tenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the ad
Tenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.
nvd