Tenda Ac6 Firmware vulnerabilities
108 known vulnerabilities affecting tenda/ac6_firmware.
Total CVEs
108
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL56HIGH41MEDIUM11
Vulnerabilities
Page 4 of 6
CVE-2023-40844P3CRITICALCVSS 9.8v15.03.05.162023-08-30
CVE-2023-40844 [CRITICAL] CWE-787 CVE-2023-40844: Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'fo
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'formWifiBasicSet.'
nvd
CVE-2023-40847P3CRITICALCVSS 9.8v15.03.05.162023-08-30
CVE-2023-40847 [CRITICAL] CWE-787 CVE-2023-40847: Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "initIpAddrInfo." In the function, it reads in a user-provided parameter, and the variable is passed to the function without any length check.
nvd
CVE-2023-40843P3CRITICALCVSS 9.8v15.03.05.162023-08-30
CVE-2023-40843 [CRITICAL] CWE-787 CVE-2023-40843: Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "su
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "sub_73004."
nvd
CVE-2023-40840P3CRITICALCVSS 9.8v15.03.05.162023-08-30
CVE-2023-40840 [CRITICAL] CWE-787 CVE-2023-40840: Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "fr
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "fromGetWirelessRepeat."
nvd
CVE-2025-31355P3CRITICALCVSS 9.8v02.03.01.1102025-08-20
CVE-2025-31355 [CRITICAL] CWE-494 CVE-2025-31355: A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda A
A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2023-24332P3HIGHCVSS 8.1v03.03.02.01_cn_tdc012024-02-21
CVE-2023-24332 [HIGH] CWE-121 CVE-2023-24332: A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01
A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.
nvd
CVE-2023-38823P3CRITICALCVSS 9.8v15.03.05.19\(6318\)2023-11-20
CVE-2023-38823 [CRITICAL] CWE-120 CVE-2023-38823: Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a rem
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
nvd
CVE-2023-40842P3CRITICALCVSS 9.8v15.03.05.162023-08-30
CVE-2023-40842 [CRITICAL] CWE-787 CVE-2023-40842: Tengda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "R
Tengda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "R7WebsSecurityHandler."
nvd
CVE-2023-40845P3CRITICALCVSS 9.8v15.03.05.162023-08-30
CVE-2023-40845 [CRITICAL] CWE-787 CVE-2023-40845: Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'su
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'sub_34FD0.' In the function, it reads user provided parameters and passes variables to the function without any length checks.
nvd
CVE-2025-50263P3HIGHCVSS 8.1v15.03.05.16_multi2025-07-03
CVE-2025-50263 [HIGH] CWE-120 CVE-2025-50263: Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.
nvd
CVE-2025-50258P3HIGHCVSS 8.1v15.03.05.16_multi2025-07-03
CVE-2025-50258 [HIGH] CWE-120 CVE-2025-50258: Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.
nvd
CVE-2025-55503P3HIGHCVSS 7.3v15.03.06.23_multi2025-08-20
CVE-2025-55503 [HIGH] CWE-121 CVE-2025-55503: Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the
Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.
nvd
CVE-2024-51116P3HIGHCVSS 8.8v15.03.06.502024-11-05
CVE-2024-51116 [HIGH] CWE-120 CVE-2024-51116: Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTP
Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.
nvd
CVE-2024-46450P3HIGHCVSS 8.1v15.03.06.502025-01-16
CVE-2024-46450 [HIGH] CWE-862 CVE-2024-46450: Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.
Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.
nvd
CVE-2025-29121P3HIGHCVSS 7.5v15.03.05.162025-03-20
CVE-2025-29121 [HIGH] CWE-121 CVE-2025-29121: A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of
A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.
nvd
CVE-2025-55498P3HIGHCVSS 7.5v15.03.06.23_multi2025-08-20
CVE-2025-55498 [HIGH] CWE-121 CVE-2025-55498: Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in t
Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.
nvd
CVE-2025-50262P3HIGHCVSS 7.5v15.03.05.16_multi2025-07-03
CVE-2025-50262 [HIGH] CWE-120 CVE-2025-50262: Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.
nvd
CVE-2025-50260P3HIGHCVSS 7.5v15.03.05.16_multi2025-07-03
CVE-2025-50260 [HIGH] CWE-121 CVE-2025-50260: Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.
nvd
CVE-2024-10280P3HIGHCVSS 7.5v15.03.06.232024-10-23
CVE-2024-10280 [HIGH] CWE-476 CVE-2024-10280: A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit
nvd
CVE-2025-46035P3HIGHCVSS 7.5v15.03.05.162025-06-12
CVE-2025-46035 [HIGH] CWE-120 CVE-2025-46035: Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial
Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated HTTP GET request to the /goform/openSchedWifi endpoint
nvd