Tenda Ac18 Firmware vulnerabilities
103 known vulnerabilities affecting tenda/ac18_firmware.
Total CVEs
103
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL46HIGH49MEDIUM8
Vulnerabilities
Page 3 of 6
CVE-2025-5608P2HIGHCVSS 8.8v15.03.05.052025-06-04
CVE-2025-5608 [HIGH] CWE-119 CVE-2025-5608: A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the fun
A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formsetreboottimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2022-38310P3CRITICALCVSS 9.8v15.03.05.05v15.03.05.19\(6318\)2022-09-07
CVE-2022-38310 [CRITICAL] CWE-787 CVE-2022-38310: Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the l
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
nvd
CVE-2022-38311P3CRITICALCVSS 9.8v15.03.05.05v15.03.05.19\(6318\)2022-09-07
CVE-2022-38311 [CRITICAL] CWE-787 CVE-2022-38311: Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the t
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.
nvd
CVE-2022-38313P3CRITICALCVSS 9.8v15.03.05.05v15.03.05.19\(6318\)2022-09-07
CVE-2022-38313 [CRITICAL] CWE-787 CVE-2022-38313: Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the t
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.
nvd
CVE-2022-38309P3CRITICALCVSS 9.8v15.03.05.05v15.03.05.19\(6318\)2022-09-07
CVE-2022-38309 [CRITICAL] CWE-787 CVE-2022-38309: Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the l
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
nvd
CVE-2022-38314P3CRITICALCVSS 9.8v15.03.05.05v15.03.05.19\(6318\)2022-09-07
CVE-2022-38314 [CRITICAL] CWE-787 CVE-2022-38314: Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the u
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.
nvd
CVE-2022-38312P3CRITICALCVSS 9.8v15.03.05.05v15.03.05.19\(6318\)2022-09-07
CVE-2022-38312 [CRITICAL] CWE-787 CVE-2022-38312: Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the l
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
nvd
CVE-2022-43260P3CRITICALCVSS 9.8v15.03.05.192022-10-18
CVE-2022-43260 [CRITICAL] CWE-787 CVE-2022-43260: Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in t
Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.
nvd
CVE-2025-0528P3HIGHCVSS 7.2v16.03.10.202025-01-17
CVE-2025-0528 [HIGH] CWE-74 CVE-2025-0528: A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and
nvd
CVE-2022-30472P3CRITICALCVSS 9.8v15.03.05.19\(6318\)2022-05-26
CVE-2022-30472 [CRITICAL] CWE-787 CVE-2022-30472: Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in fun
Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat
nvd
CVE-2022-35201P3CRITICALCVSS 9.8v15.03.05.052022-08-19
CVE-2022-35201 [CRITICAL] CVE-2022-35201: Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
nvd
CVE-2022-30476P3CRITICALCVSS 9.8v15.03.05.19\(6318\)2022-05-26
CVE-2022-30476 [CRITICAL] CWE-787 CVE-2022-30476: Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overfl
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetFirewallCfg request.
nvd
CVE-2022-30477P3CRITICALCVSS 9.8v15.03.05.19\(6318\)2022-05-26
CVE-2022-30477 [CRITICAL] CWE-787 CVE-2022-30477: Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overfl
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetClientState request.
nvd
CVE-2022-40854P3CRITICALCVSS 9.8v15.03.05.19\(6318\)2022-09-23
CVE-2022-40854 [CRITICAL] CWE-787 CVE-2022-40854: Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set
Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set
nvd
CVE-2017-16923P3HIGHCVSS 8.8vus_ac18v1.0br_v15.03.05.05_multi_td01vac18_kf_v15.03.05.19\(6318_\)_cn2017-11-21
CVE-2017-16923 [HIGH] CWE-78 CVE-2017-16923: Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_m
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticate
nvd
CVE-2018-18728P3CRITICALCVSS 9.8v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18728 [CRITICAL] CWE-78 CVE-2018-18728: An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.
nvd
CVE-2022-30474P3CRITICALCVSS 9.8v15.03.05.19\(6318\)2022-05-26
CVE-2022-30474 [CRITICAL] CWE-787 CVE-2022-30474: Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the http
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request.
nvd
CVE-2023-24166P3CRITICALCVSS 9.8v15.03.05.192023-01-26
CVE-2023-24166 [CRITICAL] CWE-787 CVE-2023-24166: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.
nvd
CVE-2022-44183P3CRITICALCVSS 9.8v15.03.05.192022-11-21
CVE-2022-44183 [CRITICAL] CWE-120 CVE-2022-44183: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.
nvd
CVE-2023-24165P3CRITICALCVSS 9.8v15.03.05.192023-01-26
CVE-2023-24165 [CRITICAL] CWE-787 CVE-2023-24165: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo.
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo.
nvd