Tenda Ac7 Firmware vulnerabilities
72 known vulnerabilities affecting tenda/ac7_firmware.
Total CVEs
72
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL28HIGH40MEDIUM4
Vulnerabilities
Page 3 of 4
CVE-2023-41562P2CRITICALCVSS 9.8v15.03.06.442023-08-30
CVE-2023-41562 [CRITICAL] CWE-787 CVE-2023-41562: Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.0
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet.
nvd
CVE-2023-41555P2CRITICALCVSS 9.8v15.03.06.442023-08-30
CVE-2023-41555 [CRITICAL] CWE-787 CVE-2023-41555: Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at
Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.
nvd
CVE-2023-41558P2CRITICALCVSS 9.8v15.03.06.442023-08-30
CVE-2023-41558 [CRITICAL] CWE-787 CVE-2023-41558: Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter timeZone at url
Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter timeZone at url /goform/SetSysTimeCfg.
nvd
CVE-2024-48826P2HIGHCVSS 8.8v15.03.06.442024-10-28
CVE-2024-48826 [HIGH] CWE-78 CVE-2024-48826: Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote atta
Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
nvd
CVE-2024-48825P2HIGHCVSS 8.8v15.03.06.442024-10-28
CVE-2024-48825 [HIGH] CWE-78 CVE-2024-48825: Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote at
Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
nvd
CVE-2023-41559P3CRITICALCVSS 9.8v15.03.06.442023-08-30
CVE-2023-41559 [CRITICAL] CWE-787 CVE-2023-41559: Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 w
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.
nvd
CVE-2023-38930P3CRITICALCVSS 9.8v15.03.06.442023-08-07
CVE-2023-38930 [CRITICAL] CWE-787 CVE-2023-38930: Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and
Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
nvd
CVE-2025-29137P3CRITICALCVSS 9.8v15.03.06.442025-03-19
CVE-2025-29137 [CRITICAL] CWE-120 CVE-2025-29137: Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fas
Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.
nvd
CVE-2024-32281P2HIGHCVSS 8.8v15.03.06.442024-04-17
CVE-2024-32281 [HIGH] CWE-77 CVE-2024-32281: Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand fu
Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.
nvd
CVE-2023-38936P3CRITICALCVSS 9.8v15.03.06.442023-08-07
CVE-2023-38936 [CRITICAL] CWE-787 CVE-2023-38936: Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
nvd
CVE-2023-38933P3CRITICALCVSS 9.8v15.03.06.442023-08-07
CVE-2023-38933 [CRITICAL] CWE-787 CVE-2023-38933: Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2
Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
nvd
CVE-2023-37714P3CRITICALCVSS 9.8v1.02023-07-14
CVE-2023-37714 [CRITICAL] CWE-787 CVE-2023-37714: Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow i
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromRouteStatic.
nvd
CVE-2023-38931P3CRITICALCVSS 9.8v15.03.06.442023-08-07
CVE-2023-38931 [CRITICAL] CWE-787 CVE-2023-38931: Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
nvd
CVE-2023-38937P3CRITICALCVSS 9.8v15.03.06.442023-08-07
CVE-2023-38937 [CRITICAL] CWE-787 CVE-2023-38937: Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
nvd
CVE-2023-37716P3CRITICALCVSS 9.8v1.02023-07-14
CVE-2023-37716 [CRITICAL] CWE-787 CVE-2023-37716: Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting.
nvd
CVE-2023-37717P3CRITICALCVSS 9.8v1.02023-07-14
CVE-2023-37717 [CRITICAL] CWE-787 CVE-2023-37717: Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient.
nvd
CVE-2018-18729P3CRITICALCVSS 9.8v15.03.06.44_cn2018-10-29
CVE-2018-18729 [CRITICAL] CWE-787 CVE-2018-18729: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy
nvd
CVE-2024-10280P3HIGHCVSS 7.5v15.03.06.442024-10-23
CVE-2024-10280 [HIGH] CWE-476 CVE-2024-10280: A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit
nvd
CVE-2018-14559P3HIGHCVSS 7.5≤ 15.03.06.44_cn2019-04-25
CVE-2018-14559 [HIGH] CWE-119 CVE-2018-14559: An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value
nvd
CVE-2018-14557P3HIGHCVSS 7.5≤ 15.03.06.44_cn2019-04-25
CVE-2018-14557 [HIGH] CWE-119 CVE-2018-14557: An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value
nvd