cbcvebase.

Tenda Ac6 Firmware vulnerabilities

108 known vulnerabilities affecting tenda/ac6_firmware.

Total CVEs
108
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL56HIGH41MEDIUM11

Vulnerabilities

Page 6 of 6
CVE-2022-41485P3HIGHCVSS 7.5v15.03.06.51_multi_tde012022-10-13
CVE-2022-41485 [HIGH] CWE-120 CVE-2022-41485: Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in t Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47ce00 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-60340P3HIGHCVSS 7.5v15.03.06.502025-10-22
CVE-2025-60340 [HIGH] CWE-120 CVE-2025-60340: Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters.
nvd
CVE-2025-25507P3MEDIUMCVSS 6.5v15.03.05.16_multi2025-02-21
CVE-2025-25507 [MEDIUM] CWE-94 CVE-2025-25507: There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the par There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.
nvd
CVE-2025-25505P3MEDIUMCVSS 6.5v15.03.05.16_multi2025-02-21
CVE-2025-25505 [MEDIUM] CWE-120 CVE-2025-25505: Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function. Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.
nvd
CVE-2022-45673P4MEDIUMCVSS 6.5v15.03.05.192022-12-02
CVE-2022-45673 [MEDIUM] CWE-352 CVE-2022-45673: Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysTo Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
nvd
CVE-2022-45674P4MEDIUMCVSS 6.5v15.03.05.192022-12-02
CVE-2022-45674 [MEDIUM] CWE-352 CVE-2022-45674: Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysTo Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
nvd
CVE-2022-40010P4MEDIUMCVSS 5.4v15.03.06.50_multi2023-06-26
CVE-2022-40010 [MEDIUM] CWE-79 CVE-2022-40010: Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-sit Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vulnerability via the deviceId parameter in the Parental Control module.
nvd
CVE-2021-40546P4MEDIUMCVSS 4.9v02.03.01.262023-09-05
CVE-2021-40546 [MEDIUM] CWE-404 CVE-2021-40546: Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) t Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi.
nvd
Tenda Ac6 Firmware vulnerabilities | cvebase