cbcvebase.

Tenda Ac18 Firmware vulnerabilities

103 known vulnerabilities affecting tenda/ac18_firmware.

Total CVEs
103
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL46HIGH49MEDIUM8

Vulnerabilities

Page 4 of 6
CVE-2023-24169P3CRITICALCVSS 9.8v15.03.05.192023-01-26
CVE-2023-24169 [CRITICAL] CWE-787 CVE-2023-24169: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.
nvd
CVE-2023-24170P3CRITICALCVSS 9.8v15.03.05.192023-01-26
CVE-2023-24170 [CRITICAL] CWE-787 CVE-2023-24170: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.
nvd
CVE-2023-24164P3CRITICALCVSS 9.8v15.03.05.192023-01-26
CVE-2023-24164 [CRITICAL] CWE-787 CVE-2023-24164: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318.
nvd
CVE-2023-24167P3CRITICALCVSS 9.8v15.03.05.192023-01-26
CVE-2023-24167 [CRITICAL] CWE-787 CVE-2023-24167: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node.
nvd
CVE-2022-44176P3CRITICALCVSS 9.8v15.03.05.192022-11-21
CVE-2022-44176 [CRITICAL] CWE-120 CVE-2022-44176: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.
nvd
CVE-2022-44175P3CRITICALCVSS 9.8v15.03.05.192022-11-21
CVE-2022-44175 [CRITICAL] CWE-120 CVE-2022-44175: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
nvd
CVE-2024-33181P3HIGHCVSS 8.8v15.03.3.10_en2024-07-16
CVE-2024-33181 [HIGH] CWE-121 CVE-2024-33181: Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parameter at ip/goform/addWifiMacFilter.
nvd
CVE-2022-44171P3CRITICALCVSS 9.8v15.03.05.192022-11-21
CVE-2022-44171 [CRITICAL] CWE-120 CVE-2022-44171: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.
nvd
CVE-2022-44178P3CRITICALCVSS 9.8v15.03.05.192022-11-21
CVE-2022-44178 [CRITICAL] CWE-120 CVE-2022-44178: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.
nvd
CVE-2022-44180P3CRITICALCVSS 9.8v15.03.05.192022-11-21
CVE-2022-44180 [CRITICAL] CWE-120 CVE-2022-44180: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.
nvd
CVE-2022-44177P3CRITICALCVSS 9.8v15.03.05.192022-11-21
CVE-2022-44177 [CRITICAL] CWE-120 CVE-2022-44177: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.
nvd
CVE-2022-44172P3CRITICALCVSS 9.8v15.03.05.192022-11-21
CVE-2022-44172 [CRITICAL] CWE-120 CVE-2022-44172: Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler. Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.
nvd
CVE-2022-44174P3CRITICALCVSS 9.8v15.03.05.052022-11-21
CVE-2022-44174 [CRITICAL] CWE-120 CVE-2022-44174: Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName. Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.
nvd
CVE-2024-57578P3HIGHCVSS 8.8v15.03.05.192025-01-16
CVE-2024-57578 [HIGH] CWE-787 CVE-2024-57578: Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in th Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm function.
nvd
CVE-2023-38823P3CRITICALCVSS 9.8v15.03.05.19\(6318\)2023-11-20
CVE-2023-38823 [CRITICAL] CWE-120 CVE-2023-38823: Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a rem Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
nvd
CVE-2024-41630P3HIGHCVSS 7.6v15.03.3.10_en2024-07-31
CVE-2024-41630 [HIGH] CWE-121 CVE-2024-41630: Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to e Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.
nvd
CVE-2024-34974P3HIGHCVSS 8.2v15.03.05.192024-05-14
CVE-2024-34974 [HIGH] CWE-125 CVE-2024-34974: Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the e Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.
nvd
CVE-2018-18729P3CRITICALCVSS 9.8v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18729 [CRITICAL] CWE-787 CVE-2018-18729: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy
nvd
CVE-2025-8182P3HIGHCVSS 7.4v15.03.05.192025-07-26
CVE-2025-8182 [HIGH] CWE-521 CVE-2025-8182: A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnera A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component Samba. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficu
nvd
CVE-2025-60662P3HIGHCVSS 7.5v15.03.05.192025-10-02
CVE-2025-60662 [HIGH] CWE-787 CVE-2025-60662: Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.
nvd
Tenda Ac18 Firmware vulnerabilities | cvebase