cbcvebase.

Tenda Ac9 Firmware vulnerabilities

92 known vulnerabilities affecting tenda/ac9_firmware.

Total CVEs
92
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL55HIGH33MEDIUM4

Vulnerabilities

Page 4 of 5
CVE-2023-38935P3CRITICALCVSS 9.8v15.03.06.42_multi2023-08-07
CVE-2023-38935 [CRITICAL] CWE-787 CVE-2023-38935: Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.
nvd
CVE-2023-37716P3CRITICALCVSS 9.8v3.02023-07-14
CVE-2023-37716 [CRITICAL] CWE-787 CVE-2023-37716: Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1. Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting.
nvd
CVE-2023-37717P3CRITICALCVSS 9.8v3.02023-07-14
CVE-2023-37717 [CRITICAL] CWE-787 CVE-2023-37717: Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1. Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient.
nvd
CVE-2024-25753P3HIGHCVSS 8.8v5.03.06.42_multi2024-02-22
CVE-2024-25753 [HIGH] CWE-121 CVE-2024-25753: Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_mul Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formSetDeviceName function.
nvd
CVE-2024-25748P3HIGHCVSS 8.8v5.03.06.42_multi2024-02-22
CVE-2024-25748 [HIGH] CWE-121 CVE-2024-25748: A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06. A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetIpMacBind function.
nvd
CVE-2023-38823P3CRITICALCVSS 9.8v15.03.05.19\(6318\)2023-11-20
CVE-2023-38823 [CRITICAL] CWE-120 CVE-2023-38823: Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a rem Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
nvd
CVE-2024-25746P3HIGHCVSS 8.8v5.03.06.42_multi2024-02-22
CVE-2024-25746 [HIGH] CWE-121 CVE-2024-25746: Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_mul Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the add_white_node function.
nvd
CVE-2025-5836P3MEDIUMCVSS 6.3v15.03.2.132025-06-07
CVE-2025-5836 [MEDIUM] CWE-74 CVE-2025-5836: A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affect A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may
nvd
CVE-2018-18729P3CRITICALCVSS 9.8v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18729 [CRITICAL] CWE-787 CVE-2018-18729: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy
nvd
CVE-2024-24543P3CRITICALCVSS 9.8v15.03.06.42_multi2024-02-05
CVE-2024-24543 [CRITICAL] CWE-787 CVE-2024-24543: Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15 Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.
nvd
CVE-2025-14286P3HIGHCVSS 7.5v15.03.05.14_multi2025-12-09
CVE-2025-14286 [HIGH] CWE-200 CVE-2025-14286: A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2024-25756P3HIGHCVSS 8.0v5.03.06.42_multi2024-02-22
CVE-2024-25756 [HIGH] CWE-121 CVE-2024-25756: A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_m A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet function.
nvd
CVE-2025-57639P3MEDIUMCVSS 6.5v1.02025-09-23
CVE-2025-57639 [MEDIUM] CWE-78 CVE-2025-57639: OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vu OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file.
nvd
CVE-2024-10280P3HIGHCVSS 7.5v15.03.2.13v15.03.05.14+2 more2024-10-23
CVE-2024-10280 [HIGH] CWE-476 CVE-2024-10280: A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit
nvd
CVE-2022-36571P3HIGHCVSS 7.2v15.03.05.192022-08-31
CVE-2022-36571 [HIGH] CWE-787 CVE-2022-36571: Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/ Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.
nvd
CVE-2018-14559P3HIGHCVSS 7.5≤ 15.03.05.19\(6318\)_cn2019-04-25
CVE-2018-14559 [HIGH] CWE-119 CVE-2018-14559: An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value
nvd
CVE-2018-14557P3HIGHCVSS 7.5≤ 15.03.05.19\(6318\)_cn2019-04-25
CVE-2018-14557 [HIGH] CWE-119 CVE-2018-14557: An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value
nvd
CVE-2022-36570P3HIGHCVSS 7.2v15.03.05.192022-08-31
CVE-2022-36570 [HIGH] CWE-787 CVE-2022-36570: Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/ Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.
nvd
CVE-2018-18708P3HIGHCVSS 7.5v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18708 [HIGH] CWE-119 CVE-2018-18708: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly u
nvd
CVE-2018-18730P3HIGHCVSS 7.5v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18730 [HIGH] CWE-119 CVE-2018-18730: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a spr
nvd
Tenda Ac9 Firmware vulnerabilities | cvebase