Tenda Ac1206 Firmware vulnerabilities
44 known vulnerabilities affecting tenda/ac1206_firmware.
Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL36HIGH6MEDIUM2
Vulnerabilities
Page 1 of 3
CVE-2025-7544P1HIGHCVSS 8.8Exploitedv15.03.06.232025-07-13
CVE-2025-7544 [HIGH] CWE-119 CVE-2025-7544: A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue aff
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used
nvd
CVE-2024-9793P1CRITICALCVSS 9.8v15.03.06.232024-10-10
CVE-2024-9793 [CRITICAL] CWE-77 CVE-2024-9793: A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerabili
A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted e
nvd
CVE-2026-0581P2CRITICALCVSS 9.8v15.03.06.232026-01-05
CVE-2026-0581 [CRITICAL] CWE-74 CVE-2026-0581: A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function f
A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection. The attack can be launched remotely. The exploit has been publicly disc
nvd
CVE-2025-10432P2CRITICALCVSS 9.8v15.03.06.232025-09-15
CVE-2025-10432 [CRITICAL] CWE-119 CVE-2025-10432: A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function check
A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function check_param_changed of the file /goform/AdvSetMacMtuWa of the component HTTP Request Handler. Performing manipulation of the argument wanMTU results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made
nvd
CVE-2025-3328P2HIGHCVSS 8.8v15.03.06.232025-04-07
CVE-2025-3328 [HIGH] CWE-119 CVE-2025-3328: A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid/timeZone leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and ma
nvd
CVE-2025-9523P2CRITICALCVSS 9.8v15.03.06.232025-08-27
CVE-2025-9523 [CRITICAL] CWE-119 CVE-2025-9523: A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlI
A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.
nvd
CVE-2024-10434P2CRITICALCVSS 9.8≤ 2024-10-272024-10-28
CVE-2024-10434 [CRITICAL] CWE-121 CVE-2024-10434: A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This a
A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ate_Tenda_mfg_check_usb/ate_Tenda_mfg_check_usb3 of the file /goform/ate. The manipulation of the argument arg leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed t
nvd
CVE-2025-4299P2CRITICALCVSS 9.8≤ 15.03.06.232025-05-06
CVE-2025-4299 [CRITICAL] CWE-119 CVE-2025-4299: A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This iss
A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2022-37810P2CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37810 [CRITICAL] CWE-78 CVE-2022-37810: Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac pa
Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
nvd
CVE-2025-4298P2CRITICALCVSS 9.8≤ 15.03.06.232025-05-06
CVE-2025-4298 [CRITICAL] CWE-119 CVE-2025-4298: A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This
A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2023-37711P2CRITICALCVSS 9.8v15.03.06.232023-07-10
CVE-2023-37711 [CRITICAL] CWE-787 CVE-2023-37711: Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the d
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.
nvd
CVE-2023-37710P2CRITICALCVSS 9.8v15.03.06.232023-07-10
CVE-2023-37710 [CRITICAL] CWE-787 CVE-2023-37710: Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the w
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
nvd
CVE-2022-37811P2CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37811 [CRITICAL] CWE-787 CVE-2022-37811: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in th
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.
nvd
CVE-2022-37815P2CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37815 [CRITICAL] CWE-787 CVE-2022-37815: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.
nvd
CVE-2022-37809P2CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37809 [CRITICAL] CWE-787 CVE-2022-37809: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.
nvd
CVE-2022-37812P2CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37812 [CRITICAL] CWE-787 CVE-2022-37812: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the firewallEn parameter in the function formSetFirewallCfg.
nvd
CVE-2022-37801P3CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37801 [CRITICAL] CWE-787 CVE-2022-37801: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the f
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
nvd
CVE-2022-37800P3CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37800 [CRITICAL] CWE-787 CVE-2022-37800: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the f
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.
nvd
CVE-2022-37798P3CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37798 [CRITICAL] CWE-787 CVE-2022-37798: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the f
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.
nvd
CVE-2022-37808P3CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37808 [CRITICAL] CWE-787 CVE-2022-37808: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.
nvd
1 / 3Next →