Tenda Ac1206 Firmware vulnerabilities

44 known vulnerabilities affecting tenda/ac1206_firmware.

Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL29HIGH11MEDIUM4

Vulnerabilities

Page 2 of 3
CVE-2022-42080HIGHCVSS 7.5v15.03.06.23_multi_td012022-10-12
CVE-2022-42080 [HIGH] CWE-787 CVE-2022-42080: Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a heap overflow via Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a heap overflow via sched_start_time parameter.
nvd
CVE-2022-42079HIGHCVSS 7.5v15.03.06.23_multi_td012022-10-12
CVE-2022-42079 [HIGH] CWE-787 CVE-2022-42079: Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWifiBasicSet.
nvd
CVE-2022-42081HIGHCVSS 7.5v15.03.06.23_multi_td012022-10-12
CVE-2022-42081 [HIGH] CWE-787 CVE-2022-42081: Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via sched_end_time parameter.
nvd
CVE-2022-42078MEDIUMCVSS 6.5v15.03.06.23_multi_td012022-10-12
CVE-2022-42078 [MEDIUM] CWE-352 CVE-2022-42078: Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (C Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
nvd
CVE-2022-42077MEDIUMCVSS 6.5v15.03.06.23_multi_td012022-10-12
CVE-2022-42077 [MEDIUM] CWE-352 CVE-2022-42077: Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (C Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
nvd
CVE-2022-37808CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37808 [CRITICAL] CWE-787 CVE-2022-37808: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the index parameter in the function formWifiWpsOOB.
nvd
CVE-2022-37811CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37811 [CRITICAL] CWE-787 CVE-2022-37811: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in th Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the startIp parameter in the function formSetPPTPServer.
nvd
CVE-2022-37815CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37815 [CRITICAL] CWE-787 CVE-2022-37815: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the PPPOEPassword parameter in the function formQuickIndex.
nvd
CVE-2022-37803CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37803 [CRITICAL] CWE-787 CVE-2022-37803: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the f Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromAddressNat.
nvd
CVE-2022-37806CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37806 [CRITICAL] CWE-787 CVE-2022-37806: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the f Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromDhcpListClient.
nvd
CVE-2022-37805CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37805 [CRITICAL] CWE-787 CVE-2022-37805: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHand Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromWizardHandle.
nvd
CVE-2022-37804CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37804 [CRITICAL] CWE-787 CVE-2022-37804: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the f Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo.
nvd
CVE-2022-37816CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37816 [CRITICAL] CWE-787 CVE-2022-37816: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBi Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetIpMacBind.
nvd
CVE-2022-37801CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37801 [CRITICAL] CWE-787 CVE-2022-37801: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the f Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
nvd
CVE-2022-37814CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37814 [CRITICAL] CWE-787 CVE-2022-37814: Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and t Tenda AC1206 V15.03.06.23 was discovered to contain multiple stack overflows via the deviceMac and the device_id parameters in the function addWifiMacFilter.
nvd
CVE-2022-37802CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37802 [CRITICAL] CWE-787 CVE-2022-37802: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the f Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the page parameter in the function fromNatStaticSetting.
nvd
CVE-2022-37800CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37800 [CRITICAL] CWE-787 CVE-2022-37800: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the f Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.
nvd
CVE-2022-37809CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37809 [CRITICAL] CWE-787 CVE-2022-37809: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.
nvd
CVE-2022-37810CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37810 [CRITICAL] CWE-78 CVE-2022-37810: Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac pa Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
nvd
CVE-2022-37813CRITICALCVSS 9.8v15.03.06.232022-08-25
CVE-2022-37813 [CRITICAL] CWE-787 CVE-2022-37813: Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.
nvd