cbcvebase.

Tenda Ac9 Firmware vulnerabilities

92 known vulnerabilities affecting tenda/ac9_firmware.

Total CVEs
92
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL55HIGH33MEDIUM4

Vulnerabilities

Page 2 of 5
CVE-2022-25433P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25433 [CRITICAL] CWE-787 CVE-2022-25433: Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the savep Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo function.
nvd
CVE-2022-25435P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25435 [CRITICAL] CWE-787 CVE-2022-25435: Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetSt Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function.
nvd
CVE-2022-25427P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25427 [CRITICAL] CWE-787 CVE-2022-25427: Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in t Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
nvd
CVE-2022-25440P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25440 [CRITICAL] CWE-787 CVE-2022-25440: Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
nvd
CVE-2022-25439P2CRITICALCVSS 9.8v15.03.2.212022-03-18
CVE-2022-25439 [CRITICAL] CWE-787 CVE-2022-25439: Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIp Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
nvd
CVE-2025-45429P2CRITICALCVSS 9.8v15.03.05.14_multi2025-04-23
CVE-2025-45429 [CRITICAL] CWE-121 CVE-2025-45429: In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerabili In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.
nvd
CVE-2023-41556P2CRITICALCVSS 9.8v5.03.06.42_multi2023-08-30
CVE-2023-41556 [CRITICAL] CWE-787 CVE-2023-41556: Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 w Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetIpMacBind.
nvd
CVE-2025-45428P2CRITICALCVSS 9.8v15.03.05.14_multi2025-04-23
CVE-2025-45428 [CRITICAL] CWE-121 CVE-2025-45428: In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRe In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
nvd
CVE-2025-5839P2HIGHCVSS 8.8v15.03.2.132025-06-07
CVE-2025-5839 [HIGH] CWE-119 CVE-2025-5839: A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to
nvd
CVE-2025-22946P2CRITICALCVSS 9.8v15.03.05.192025-01-10
CVE-2025-22946 [CRITICAL] CWE-120 CVE-2025-22946: Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDev Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.
nvd
CVE-2025-29385P2CRITICALCVSS 9.8v15.03.05.142025-03-14
CVE-2025-29385 [CRITICAL] CWE-787 CVE-2025-29385: In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
nvd
CVE-2025-29386P2CRITICALCVSS 9.8v15.03.05.142025-03-14
CVE-2025-29386 [CRITICAL] CWE-787 CVE-2025-29386: In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overf In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
nvd
CVE-2023-41560P2CRITICALCVSS 9.8v15.03.06.42_multi2023-08-30
CVE-2023-41560 [CRITICAL] CWE-787 CVE-2023-41560: Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter firewallE Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter firewallEn at url /goform/SetFirewallCfg.
nvd
CVE-2023-41553P2CRITICALCVSS 9.8v5.03.06.42_multi2023-08-30
CVE-2023-41553 [CRITICAL] CWE-787 CVE-2023-41553: Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contai Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetStaticRouteCfg.
nvd
CVE-2023-41552P2CRITICALCVSS 9.8v5.03.06.42_multi2023-08-30
CVE-2023-41552 [CRITICAL] CWE-787 CVE-2023-41552: Tenda AC7 V1.0 V15.03.06.44 and Tenda AC9 V3.0 V15.03.06.42_multi were discovered to contain a stack Tenda AC7 V1.0 V15.03.06.44 and Tenda AC9 V3.0 V15.03.06.42_multi were discovered to contain a stack overflow via parameter ssid at url /goform/fast_setting_wifi_set.
nvd
CVE-2023-41554P2CRITICALCVSS 9.8v5.03.06.42_multi2023-08-30
CVE-2023-41554 [CRITICAL] CWE-787 CVE-2023-41554: Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter wpapsk_cr Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter wpapsk_crypto at url /goform/WifiExtraSet.
nvd
CVE-2023-41563P2CRITICALCVSS 9.8v15.03.06.42_multi2023-08-30
CVE-2023-41563 [CRITICAL] CWE-787 CVE-2023-41563: Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contai Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.
nvd
CVE-2023-41561P2CRITICALCVSS 9.8v15.03.06.42_multi2023-08-30
CVE-2023-41561 [CRITICAL] CWE-787 CVE-2023-41561: Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contai Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.
nvd
CVE-2022-36273P2CRITICALCVSS 9.8v15.03.2.21_cn2022-08-16
CVE-2022-36273 [CRITICAL] CWE-78 CVE-2022-36273: Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg. Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.
nvd
CVE-2022-27016P2CRITICALCVSS 9.8v15.03.2.21_cn2022-04-07
CVE-2022-27016 [CRITICAL] CWE-787 CVE-2022-27016: There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn.
nvd
Tenda Ac9 Firmware vulnerabilities | cvebase