cbcvebase.

Tenda Ac9 Firmware vulnerabilities

92 known vulnerabilities affecting tenda/ac9_firmware.

Total CVEs
92
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL55HIGH33MEDIUM4

Vulnerabilities

Page 1 of 5
CVE-2018-14558P1CRITICALCVSS 9.8KEV≤ 15.03.05.19\(6318\)_cn2018-10-30
CVE-2018-14558 [CRITICAL] CWE-78 CVE-2018-14558: An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occur
nvd
CVE-2025-10442P2HIGHCVSS 8.8v15.03.05.142025-09-15
CVE-2025-10442 [HIGH] CWE-77 CVE-2025-10442: A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeC A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2026-6016P2HIGHCVSS 8.8v15.03.02.132026-04-10
CVE-2026-6016 [HIGH] CWE-119 CVE-2026-6016: A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd o A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.
nvd
CVE-2024-42634P2CRITICALCVSS 9.8v15.03.06.422024-08-16
CVE-2024-42634 [CRITICAL] CWE-94 CVE-2024-42634: A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03. A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.
nvd
CVE-2026-6015P2HIGHCVSS 8.8v15.03.02.132026-04-10
CVE-2026-6015 [HIGH] CWE-119 CVE-2026-6015: A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be u
nvd
CVE-2022-25434P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25434 [CRITICAL] CWE-787 CVE-2022-25434: Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function.
nvd
CVE-2025-10443P2HIGHCVSS 8.8v15.03.05.142025-09-15
CVE-2025-10443 [HIGH] CWE-119 CVE-2025-10443: A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability aff A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
nvd
CVE-2022-25414P2CRITICALCVSS 9.8vv15.03.2.21_cn2022-02-24
CVE-2022-25414 [CRITICAL] CWE-787 CVE-2022-25414: Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR. Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.
nvd
CVE-2025-44877P2CRITICALCVSS 9.8v15.03.06.42_multi2025-05-02
CVE-2025-44877 [CRITICAL] CWE-77 CVE-2025-44877: Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSa Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-44872P2CRITICALCVSS 9.8v15.03.06.42_multi2025-05-02
CVE-2025-44872 [CRITICAL] CWE-77 CVE-2025-44872: Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUs Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2025-22949P2CRITICALCVSS 9.8v15.03.05.192025-01-10
CVE-2025-22949 [CRITICAL] CWE-77 CVE-2025-22949: Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, whic Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.
nvd
CVE-2025-5847P2HIGHCVSS 8.8v15.03.2.132025-06-08
CVE-2025-5847 [HIGH] CWE-119 CVE-2025-5847: A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The attack can be launched remotely. The ex
nvd
CVE-2025-45042P2CRITICALCVSS 9.8v15.03.05.142025-05-05
CVE-2025-45042 [CRITICAL] CWE-77 CVE-2025-45042: Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet fu Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
nvd
CVE-2025-29384P2CRITICALCVSS 9.8v15.03.05.142025-03-14
CVE-2025-29384 [CRITICAL] CWE-787 CVE-2025-29384: In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack ov In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
nvd
CVE-2022-25441P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25441 [CRITICAL] CWE-78 CVE-2022-25441: Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via t Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function.
nvd
CVE-2022-25438P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25438 [CRITICAL] CWE-78 CVE-2022-25438: Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via t Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function.
nvd
CVE-2020-26728P2CRITICALCVSS 9.8v15.03.06.42_multiv15.03.05.19\(6318\)_cn2022-02-11
CVE-2020-26728 [CRITICAL] CVE-2020-26728: A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19( A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request.
nvd
CVE-2022-26278P2CRITICALCVSS 9.8v15.03.2.21_cn2022-03-28
CVE-2022-26278 [CRITICAL] CWE-787 CVE-2022-26278: Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the Po Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.
nvd
CVE-2022-25428P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25428 [CRITICAL] CWE-787 CVE-2022-25428: Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the s Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo function.
nvd
CVE-2022-25437P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25437 [CRITICAL] CWE-787 CVE-2022-25437: Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVi Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.
nvd
Tenda Ac9 Firmware vulnerabilities | cvebase