Tenda Ac10 Firmware vulnerabilities
92 known vulnerabilities affecting tenda/ac10_firmware.
Total CVEs
92
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL47HIGH31MEDIUM14
Vulnerabilities
Page 4 of 5
CVE-2024-33365P3HIGHCVSS 7.5v16.03.10.202024-07-29
CVE-2024-33365 [HIGH] CWE-120 CVE-2024-33365: Buffer Overflow vulnerability in Tenda AC10 v4 US_AC10V4.0si_V16.03.10.20_cn allows a remote attacke
Buffer Overflow vulnerability in Tenda AC10 v4 US_AC10V4.0si_V16.03.10.20_cn allows a remote attacker to execute arbitrary code via the Virtual_Data_Check function in the bin/httpd component.
nvd
CVE-2024-10280P3HIGHCVSS 7.5v16.03.10.13v16.03.10.20+2 more2024-10-23
CVE-2024-10280 [HIGH] CWE-476 CVE-2024-10280: A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit
nvd
CVE-2018-14559P3HIGHCVSS 7.5≤ 15.03.06.23_cn2019-04-25
CVE-2018-14559 [HIGH] CWE-119 CVE-2018-14559: An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value
nvd
CVE-2018-14557P3HIGHCVSS 7.5≤ 15.03.06.23_cn2019-04-25
CVE-2018-14557 [HIGH] CWE-119 CVE-2018-14557: An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value
nvd
CVE-2025-57215P3HIGHCVSS 7.5v16.03.10.202025-08-28
CVE-2025-57215 [HIGH] CWE-121 CVE-2025-57215: Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to contain a stack overflow via the function ge
Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to contain a stack overflow via the function get_parentControl_list_Info.
nvd
CVE-2018-18708P3HIGHCVSS 7.5v15.03.06.23_cn2018-10-29
CVE-2018-18708 [HIGH] CWE-119 CVE-2018-18708: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly u
nvd
CVE-2018-18730P3HIGHCVSS 7.5v15.03.06.23_cn2018-10-29
CVE-2018-18730 [HIGH] CWE-119 CVE-2018-18730: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a spr
nvd
CVE-2018-18706P3HIGHCVSS 7.5v15.03.06.23_cn2018-10-29
CVE-2018-18706 [HIGH] CWE-119 CVE-2018-18706: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a
nvd
CVE-2025-25457P3HIGHCVSS 7.5v16.03.10.202025-04-17
CVE-2025-25457 [HIGH] CWE-121 CVE-2025-25457: Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.
nvd
CVE-2025-25455P3HIGHCVSS 7.5v16.03.10.202025-04-17
CVE-2025-25455 [HIGH] CWE-121 CVE-2025-25455: Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
nvd
CVE-2025-25454P3HIGHCVSS 7.5v16.03.10.202025-04-17
CVE-2025-25454 [HIGH] CWE-121 CVE-2025-25454: Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
nvd
CVE-2018-18707P3HIGHCVSS 7.5v15.03.06.23_cn2018-10-29
CVE-2018-18707 [HIGH] CWE-119 CVE-2018-18707: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variab
nvd
CVE-2018-18731P3HIGHCVSS 7.5v15.03.06.23_cn2018-10-29
CVE-2018-18731 [HIGH] CWE-119 CVE-2018-18731: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a lo
nvd
CVE-2018-18709P3HIGHCVSS 7.5v15.03.06.23_cn2018-10-29
CVE-2018-18709 [HIGH] CWE-119 CVE-2018-18709: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local
nvd
CVE-2018-18732P3HIGHCVSS 7.5v15.03.06.23_cn2018-10-29
CVE-2018-18732 [HIGH] CWE-119 CVE-2018-18732: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a loc
nvd
CVE-2018-18727P3HIGHCVSS 7.5v15.03.06.23_cn2018-10-29
CVE-2018-18727 [HIGH] CWE-119 CVE-2018-18727: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a lo
nvd
CVE-2022-46109P3HIGHCVSS 7.5v15.03.06.232022-12-16
CVE-2022-46109 [HIGH] CWE-787 CVE-2022-46109: Tenda AC15 V15.03.06.23 is vulnerable to Buffer Overflow via function formSetClientState.
Tenda AC15 V15.03.06.23 is vulnerable to Buffer Overflow via function formSetClientState.
nvd
CVE-2025-9309P3HIGHCVSS 7.0v16.03.10.132025-08-21
CVE-2025-9309 [HIGH] CWE-259 CVE-2025-9309: A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /et
A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Performing manipulation results in hard-coded credentials. The attack needs to be approached locally. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The expl
nvd
CVE-2025-57220P4MEDIUMCVSS 5.3v16.03.10.09_multi_tde012025-08-28
CVE-2025-57220 [MEDIUM] CWE-20 CVE-2025-57220: An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 t
An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet.
nvd
CVE-2025-57218P4MEDIUMCVSS 5.3v16.03.10.09_multi_tde012025-08-28
CVE-2025-57218 [MEDIUM] CWE-121 CVE-2025-57218: Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the
Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sub_46284C.
nvd