cbcvebase.

Tenda Ax12 Firmware vulnerabilities

31 known vulnerabilities affecting tenda/ax12_firmware.

Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH16MEDIUM6

Vulnerabilities

Page 2 of 2
CVE-2022-24143P3HIGHCVSS 7.5v22.03.01.2_cn2022-02-04
CVE-2022-24143 [HIGH] CWE-787 CVE-2022-24143: Tenda AX3 v16.03.12.10_CN and AX12 22.03.01.2_CN was discovered to contain a stack overflow in the f Tenda AX3 v16.03.12.10_CN and AX12 22.03.01.2_CN was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.
nvd
CVE-2022-25560P3HIGHCVSS 7.5v22.03.01.212022-03-10
CVE-2022-25560 [HIGH] CWE-787 CVE-2022-25560: Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_4327CC. This Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_4327CC. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.
nvd
CVE-2022-25561P3HIGHCVSS 7.5v22.03.01.212022-03-10
CVE-2022-25561 [HIGH] CWE-787 CVE-2022-25561: Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42DE00. This Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42DE00. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.
nvd
CVE-2022-25556P3HIGHCVSS 7.5v22.03.01.212022-03-10
CVE-2022-25556 [HIGH] CWE-787 CVE-2022-25556: Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42E328. This Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42E328. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.
nvd
CVE-2025-29215P3MEDIUMCVSS 6.5v22.03.01.46_cn2025-03-20
CVE-2025-29215 [MEDIUM] CWE-121 CVE-2025-29215: Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList.
nvd
CVE-2023-49427P3HIGHCVSS 7.5v22.03.01.462024-01-10
CVE-2023-49427 [HIGH] CWE-787 CVE-2023-49427: Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.
nvd
CVE-2024-40412P4MEDIUMCVSS 6.8v22.03.01.462024-07-10
CVE-2024-40412 [MEDIUM] CWE-121 CVE-2024-40412: Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.
nvd
CVE-2022-27375P4MEDIUMCVSS 6.5v22.03.01.21_cn2022-04-25
CVE-2022-27375 [MEDIUM] CWE-352 CVE-2022-27375: Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the fun Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.
nvd
CVE-2022-27374P4MEDIUMCVSS 6.5v22.03.01.21_cn2022-04-25
CVE-2022-27374 [MEDIUM] CWE-352 CVE-2022-27374: Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the fun Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.
nvd
CVE-2024-40503P4MEDIUMCVSS 6.5v16.03.49.18_cn2024-07-16
CVE-2024-40503 [MEDIUM] CWE-940 CVE-2024-40503: An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via t An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packet handling.
nvd
CVE-2022-37292P4MEDIUMCVSS 5.5v22.03.01.21_cn2022-08-25
CVE-2022-37292 [MEDIUM] CWE-787 CVE-2022-37292: Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_4 Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, which satisfies the request of the upper-level interface function sub_430124, that is, handles the post request under /goform/SetIpMacBind.
nvd
Tenda Ax12 Firmware vulnerabilities | cvebase