cbcvebase.

Tenda Ac9 Firmware vulnerabilities

92 known vulnerabilities affecting tenda/ac9_firmware.

Total CVEs
92
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL55HIGH33MEDIUM4

Vulnerabilities

Page 5 of 5
CVE-2018-18706P3HIGHCVSS 7.5v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18706 [HIGH] CWE-119 CVE-2018-18706: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a
nvd
CVE-2025-57638P3HIGHCVSS 7.5v1.02025-09-23
CVE-2025-57638 [HIGH] CWE-122 CVE-2025-57638: Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value. Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.
nvd
CVE-2018-18707P3HIGHCVSS 7.5v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18707 [HIGH] CWE-119 CVE-2018-18707: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variab
nvd
CVE-2018-18731P3HIGHCVSS 7.5v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18731 [HIGH] CWE-119 CVE-2018-18731: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a lo
nvd
CVE-2018-18709P3HIGHCVSS 7.5v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18709 [HIGH] CWE-119 CVE-2018-18709: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local
nvd
CVE-2018-18732P3HIGHCVSS 7.5v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18732 [HIGH] CWE-119 CVE-2018-18732: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a loc
nvd
CVE-2018-18727P3HIGHCVSS 7.5v15.03.05.19\(6318\)_cn2018-10-29
CVE-2018-18727 [HIGH] CWE-119 CVE-2018-18727: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a lo
nvd
CVE-2025-29387P3HIGHCVSS 7.1v15.03.05.142025-03-14
CVE-2025-29387 [HIGH] CWE-787 CVE-2025-29387: In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
nvd
CVE-2025-9731P3HIGHCVSS 7.0v15.03.05.192025-08-31
CVE-2025-9731 [HIGH] CWE-259 CVE-2025-9731: A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials. It is possible to launch the attack on the local host. The attack's complexity is rated as high. The exploitability is regarded as diff
nvd
CVE-2017-16936P3MEDIUMCVSS 6.5vus_ac9v1.0br_v15.03.05.14_multi_td01vac9_kf_v15.03.05.19\(6318_\)_cn2017-11-24
CVE-2017-16936 [MEDIUM] CWE-22 CVE-2017-16936: Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14 Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenti
nvd
CVE-2025-5900P4HIGHCVSS 7.1v15.03.2.132025-06-09
CVE-2025-5900 [HIGH] CWE-352 CVE-2025-5900: A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affec A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2021-42659P4MEDIUMCVSS 6.5v15.03.05.19\(6318\)v15.03.06.42_multi2022-05-24
CVE-2021-42659 [MEDIUM] CWE-119 CVE-2021-42659: There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devic There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long list parameter occurs.
nvd
Tenda Ac9 Firmware vulnerabilities | cvebase