cbcvebase.

Tenda Ac10U vulnerabilities

26 known vulnerabilities affecting tenda/ac10u.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH14

Vulnerabilities

Page 2 of 2
CVE-2024-0923P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0923 [CRITICAL] CWE-121 CVE-2024-0923: A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_T A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The ident
nvd
CVE-2024-0928P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0928 [CRITICAL] CWE-121 CVE-2024-0928: A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been declared as critical. A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been declared as critical. Affected by this vulnerability is the function fromDhcpListClient. The manipulation of the argument page/listN leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The
nvd
CVE-2025-15215P2HIGHCVSS 8.8v15.03.06.48v15.03.06.492025-12-30
CVE-2025-15215 [HIGH] CWE-119 CVE-2025-15215: A vulnerability was determined in Tenda AC10U 15.03.06.48/15.03.06.49. This affects the function for A vulnerability was determined in Tenda AC10U 15.03.06.48/15.03.06.49. This affects the function formSetPPTPUserList of the file /goform/setPptpUserList of the component HTTP POST Request Handler. This manipulation of the argument list causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and m
nvd
CVE-2024-0929P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0929 [CRITICAL] CWE-121 CVE-2024-0929: A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Aff A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Affected by this issue is the function fromNatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252134 is the
nvd
CVE-2024-0927P2CRITICALCVSS 9.8v15.03.06.49_multi_TDE012024-01-26
CVE-2024-0927 [CRITICAL] CWE-121 CVE-2024-0927: A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been classified as critical A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been classified as critical. Affected is the function fromAddressNat. The manipulation of the argument entrys/mitInterface/page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The
nvd
CVE-2024-10280P3HIGHCVSS 7.5v202410222024-10-23
CVE-2024-10280 [HIGH] CWE-476 CVE-2024-10280: A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit
nvd