cbcvebase.

Tenda Ac10U vulnerabilities

26 known vulnerabilities affecting tenda/ac10u.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH14

Vulnerabilities

Page 1 of 2
CVE-2024-0930P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0930 [CRITICAL] CWE-121 CVE-2024-0930: A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This a A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function fromSetWirelessRepeat. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associate
nvd
CVE-2024-2853P2CRITICALCVSS 9.8v15.03.06.48v15.03.06.492024-03-24
CVE-2024-2853 [CRITICAL] CWE-78 CVE-2024-2853: A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. It has been rated as critical. Thi A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. It has been rated as critical. This issue affects the function formSetSambaConf of the file /goform/setsambacfg. The manipulation of the argument usbName leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. T
nvd
CVE-2025-15218P2HIGHCVSS 8.8v15.03.06.48v15.03.06.492025-12-30
CVE-2025-15218 [HIGH] CWE-119 CVE-2025-15218: A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49. Affected by this vulnerabilit A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Parameter Handler. Executing a manipulation of the argument lanMask can lead to buffer overflow. The attack can be launched remotely. The exploit has been ma
nvd
CVE-2024-2707P2HIGHCVSS 8.8v15.03.06.492024-03-20
CVE-2024-2707 [HIGH] CWE-78 CVE-2024-2707: A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical. This vulnerabi A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257458 is
nvd
CVE-2024-2708P2HIGHCVSS 8.8v15.03.06.492024-03-20
CVE-2024-2708 [HIGH] CWE-121 CVE-2024-2708: A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical. This issue affects A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical. This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated
nvd
CVE-2024-2706P2HIGHCVSS 8.8v15.03.06.492024-03-20
CVE-2024-2706 [HIGH] CWE-121 CVE-2024-2706: A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49. This affect A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49. This affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of the argument index leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Th
nvd
CVE-2024-0926P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0926 [CRITICAL] CWE-121 CVE-2024-0926: A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This is A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This issue affects the function formWifiWpsOOB. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this
nvd
CVE-2024-0932P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0932 [CRITICAL] CWE-121 CVE-2024-0932: A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_T A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This issue affects the function setSmartPowerManagement. The manipulation of the argument time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifi
nvd
CVE-2024-2704P2HIGHCVSS 8.8v15.03.06.492024-03-20
CVE-2024-2704 [HIGH] CWE-121 CVE-2024-2704: A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49. Affected by this vulner A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49. Affected by this vulnerability is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be u
nvd
CVE-2024-2763P2HIGHCVSS 8.8v15.03.06.482024-03-21
CVE-2024-2763 [HIGH] CWE-121 CVE-2024-2763: A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affect A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is the function formSetCfm of the file goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The
nvd
CVE-2024-2764P2HIGHCVSS 8.8v15.03.06.482024-03-21
CVE-2024-2764 [HIGH] CWE-121 CVE-2024-2764: A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affect A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument endIP leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be use
nvd
CVE-2024-2705P2HIGHCVSS 8.8v1.0v15.03.06.492024-03-20
CVE-2024-2705 [HIGH] CWE-121 CVE-2024-2705: A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49. Af A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49. Affected by this issue is the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and ma
nvd
CVE-2024-0924P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0924 [CRITICAL] CWE-121 CVE-2024-0924: A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49_multi_TDE01. A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function formSetPPTPServer. The manipulation of the argument startIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier V
nvd
CVE-2024-2703P2HIGHCVSS 8.8v15.03.06.492024-03-20
CVE-2024-2703 [HIGH] CWE-121 CVE-2024-2703: A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49. Affected is the fu A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49. Affected is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-25745
nvd
CVE-2024-2710P2HIGHCVSS 8.8v15.03.06.492024-03-20
CVE-2024-2710 [HIGH] CWE-121 CVE-2024-2710: A vulnerability was found in Tenda AC10U 15.03.06.49. It has been declared as critical. Affected by A vulnerability was found in Tenda AC10U 15.03.06.49. It has been declared as critical. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and m
nvd
CVE-2024-2709P2HIGHCVSS 8.8v15.03.06.492024-03-20
CVE-2024-2709 [HIGH] CWE-121 CVE-2024-2709: A vulnerability was found in Tenda AC10U 15.03.06.49. It has been classified as critical. Affected i A vulnerability was found in Tenda AC10U 15.03.06.49. It has been classified as critical. Affected is the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used
nvd
CVE-2024-2711P2HIGHCVSS 8.8v15.03.06.482024-03-20
CVE-2024-2711 [HIGH] CWE-121 CVE-2024-2711: A vulnerability was found in Tenda AC10U 15.03.06.48. It has been rated as critical. Affected by thi A vulnerability was found in Tenda AC10U 15.03.06.48. It has been rated as critical. Affected by this issue is the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the argument deviceMac leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be us
nvd
CVE-2024-0925P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0925 [CRITICAL] CWE-121 CVE-2024-0925: A vulnerability has been found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. Th A vulnerability has been found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This vulnerability affects the function formSetVirtualSer. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-252130 is the
nvd
CVE-2024-0931P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0931 [CRITICAL] CWE-121 CVE-2024-0931: A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. This vulner A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. This vulnerability affects the function saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The ident
nvd
CVE-2024-0922P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0922 [CRITICAL] CWE-121 CVE-2024-0922: A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this vulnerability is the function formQuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated
nvd
Tenda Ac10U vulnerabilities | cvebase