Tenda Ac10 Firmware vulnerabilities
92 known vulnerabilities affecting tenda/ac10_firmware.
Total CVEs
92
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL47HIGH31MEDIUM14
Vulnerabilities
Page 5 of 5
CVE-2025-57217P4MEDIUMCVSS 5.3v16.03.10.09_multi_tde012025-08-28
CVE-2025-57217 [MEDIUM] CWE-121 CVE-2025-57217: Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the
Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter in the function R7WebsSecurityHandler.
nvd
CVE-2023-34571P4MEDIUMCVSS 6.7vus_ac10v4.0si_v16.03.10.13_cn2023-06-08
CVE-2023-34571 [MEDIUM] CWE-787 CVE-2023-34571: Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet.
nvd
CVE-2023-34570P4MEDIUMCVSS 6.7vus_ac10v4.0si_v16.03.10.13_cn2023-06-08
CVE-2023-34570 [MEDIUM] CWE-787 CVE-2023-34570: Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.
nvd
CVE-2023-34567P4MEDIUMCVSS 6.7vus_ac10v4.0si_v16.03.10.13_cn2023-06-08
CVE-2023-34567 [MEDIUM] CWE-787 CVE-2023-34567: Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.
nvd
CVE-2023-34569P4MEDIUMCVSS 6.7vus_ac10v4.0si_v16.03.10.13_cn2023-06-08
CVE-2023-34569 [MEDIUM] CWE-787 CVE-2023-34569: Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.
nvd
CVE-2025-44175P4MEDIUMCVSS 5.4v16.03.10.132025-05-12
CVE-2025-44175 [MEDIUM] CWE-120 CVE-2025-44175: Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.
Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.
nvd
CVE-2025-57219P4MEDIUMCVSS 5.3v16.03.10.09_multi_tde012025-08-28
CVE-2025-57219 [MEDIUM] CWE-284 CVE-2025-57219: Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_
Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components via a crafted request.
nvd
CVE-2023-34568P4MEDIUMCVSS 6.7vus_ac10v4.0si_v16.03.10.13_cn2023-06-08
CVE-2023-34568 [MEDIUM] CWE-787 CVE-2023-34568: Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.
nvd
CVE-2025-67074P4MEDIUMCVSS 6.5v16.03.10.202025-12-17
CVE-2025-67074 [MEDIUM] CWE-120 CVE-2025-67074: A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.0
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serverName`) to /goform/AdvSetMacMtuWan.
nvd
CVE-2025-25458P4MEDIUMCVSS 4.6v16.03.10.202025-04-15
CVE-2025-25458 [MEDIUM] CWE-120 CVE-2025-25458: Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
nvd
CVE-2025-25453P4MEDIUMCVSS 4.6v16.03.10.202025-04-15
CVE-2025-25453 [MEDIUM] CWE-120 CVE-2025-25453: Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
nvd
CVE-2024-25373P4MEDIUMCVSS 4.6v16.03.10.202024-02-15
CVE-2024-25373 [MEDIUM] CWE-120 CVE-2024-25373: Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the
Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.
nvd
← Previous5 / 5