Tenda Ac500 Firmware vulnerabilities

16 known vulnerabilities affecting tenda/ac500_firmware.

Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH7MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-7586HIGHCVSS 7.4v2.0.1.9\(1307\)2025-07-14
CVE-2025-7586 [HIGH] CWE-119 CVE-2025-7586: A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. Affected b A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. Affected by this vulnerability is the function formSetAPCfg of the file /goform/setWtpData. The manipulation of the argument radio_2g_1 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may b
nvd
CVE-2024-10280HIGHCVSS 7.1v1.0.0.14v1.0.0.16+1 more2024-10-23
CVE-2024-10280 [HIGH] CWE-476 CVE-2024-10280: A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit
nvd
CVE-2024-32318CRITICALCVSS 9.8v2.0.1.9\(1307\)2024-04-17
CVE-2024-32318 [CRITICAL] CWE-121 CVE-2024-32318: Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.
nvd
CVE-2024-3907CRITICALCVSS 9.8v2.0.1.9\(1307\)2024-04-17
CVE-2024-3907 [HIGH] CWE-121 CVE-2024-3907: A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been rated as critical. This issue af A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been rated as critical. This issue affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated i
nvd
CVE-2024-3909CRITICALCVSS 9.8v2.0.1.9\(1307\)2024-04-17
CVE-2024-3909 [HIGH] CWE-121 CVE-2024-3909: A vulnerability classified as critical was found in Tenda AC500 2.0.1.9(1307). Affected by this vuln A vulnerability classified as critical was found in Tenda AC500 2.0.1.9(1307). Affected by this vulnerability is the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Th
nvd
CVE-2024-3908CRITICALCVSS 9.8v2.0.1.9\(1307\)2024-04-17
CVE-2024-3908 [MEDIUM] CWE-77 CVE-2024-3908: A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this v
nvd
CVE-2023-46060HIGHCVSS 7.5v2.0.1.92024-04-17
CVE-2023-46060 [HIGH] CWE-120 CVE-2023-46060: A Buffer Overflow vulnerability in Tenda AC500 v.2.0.1.9 allows a remote attacker to cause a denial A Buffer Overflow vulnerability in Tenda AC500 v.2.0.1.9 allows a remote attacker to cause a denial of service via the port parameter at the goform/setVlanInfo component.
nvd
CVE-2024-3906HIGHCVSS 8.8v2.0.1.9\(1307\)2024-04-17
CVE-2024-3906 [HIGH] CWE-121 CVE-2024-3906: A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. This vulne A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be
nvd
CVE-2024-3905HIGHCVSS 8.8v2.0.1.9\(1307\)2024-04-17
CVE-2024-3905 [HIGH] CWE-121 CVE-2024-3905: A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been classified as critical. This aff A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been classified as critical. This affects the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may b
nvd
CVE-2024-3910HIGHCVSS 8.8v2.0.1.9\(1307\)2024-04-17
CVE-2024-3910 [HIGH] CWE-121 CVE-2024-3910: A vulnerability, which was classified as critical, has been found in Tenda AC500 2.0.1.9(1307). Affe A vulnerability, which was classified as critical, has been found in Tenda AC500 2.0.1.9(1307). Affected by this issue is the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may
nvd
CVE-2024-32320MEDIUMCVSS 5.9v2.0.1.9\(1307\)2024-04-17
CVE-2024-32320 [MEDIUM] CWE-121 CVE-2024-32320: Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function.
nvd
CVE-2024-32316MEDIUMCVSS 6.5v2.0.1.9\(1307\)2024-04-17
CVE-2024-32316 [MEDIUM] CWE-121 CVE-2024-32316: Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient fun Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.
nvd
CVE-2024-32314LOWCVSS 3.8v2.0.1.9\(1307\)2024-04-17
CVE-2024-32314 [LOW] CWE-77 CVE-2024-32314: Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeComman Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
nvd
CVE-2023-25233CRITICALCVSS 9.8v2.0.1.9\(1307\)2023-02-27
CVE-2023-25233 [CRITICAL] CWE-787 CVE-2023-25233: Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via paramete Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.
nvd
CVE-2023-25234CRITICALCVSS 9.8v2.0.1.9\(1307\)2023-02-27
CVE-2023-25234 [CRITICAL] CWE-787 CVE-2023-25234: Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameter Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.
nvd
CVE-2023-25235HIGHCVSS 7.5v2.0.1.9\(1307\)2023-02-27
CVE-2023-25235 [HIGH] CWE-787 CVE-2023-25235: Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parame Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid.
nvd