Tenda Ax1803 Firmware vulnerabilities
60 known vulnerabilities affecting tenda/ax1803_firmware.
Total CVEs
60
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL31HIGH27MEDIUM2
Vulnerabilities
Page 2 of 3
CVE-2023-51955P2CRITICALCVSS 9.8v1.0.0.12024-01-10
CVE-2023-51955 [CRITICAL] CWE-787 CVE-2023-51955: Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the functi
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
nvd
CVE-2023-49043P3CRITICALCVSS 9.8v1.0.0.12023-11-27
CVE-2023-49043 [CRITICAL] CWE-787 CVE-2023-49043: Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrar
Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat.
nvd
CVE-2023-51967P2CRITICALCVSS 9.8v1.0.0.12024-01-10
CVE-2023-51967 [CRITICAL] CWE-787 CVE-2023-51967: Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getI
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.
nvd
CVE-2023-51964P2CRITICALCVSS 9.8v1.0.0.12024-01-10
CVE-2023-51964 [CRITICAL] CWE-787 CVE-2023-51964: Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setI
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
nvd
CVE-2023-51954P2CRITICALCVSS 9.8v1.0.0.12024-01-10
CVE-2023-51954 [CRITICAL] CWE-787 CVE-2023-51954: Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function form
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.
nvd
CVE-2023-51958P2CRITICALCVSS 9.8v1.0.0.12024-01-10
CVE-2023-51958 [CRITICAL] CWE-787 CVE-2023-51958: Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function form
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
nvd
CVE-2022-40876P2CRITICALCVSS 9.8v1.0.0.12022-10-27
CVE-2022-40876 [CRITICAL] CWE-787 CVE-2022-40876: In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed,
In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).
nvd
CVE-2023-51970P3CRITICALCVSS 9.8v1.0.0.12024-01-10
CVE-2023-51970 [CRITICAL] CWE-787 CVE-2023-51970: Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function form
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
nvd
CVE-2023-51962P3CRITICALCVSS 9.8v1.0.0.12024-01-10
CVE-2023-51962 [CRITICAL] CWE-787 CVE-2023-51962: Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setI
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.
nvd
CVE-2023-51953P3CRITICALCVSS 9.8v1.0.0.12024-01-10
CVE-2023-51953 [CRITICAL] CWE-787 CVE-2023-51953: Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function form
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
nvd
CVE-2023-51957P3CRITICALCVSS 9.8v1.0.0.12024-01-10
CVE-2023-51957 [CRITICAL] CWE-787 CVE-2023-51957: Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function form
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
nvd
CVE-2022-28572P3HIGHCVSS 8.8v1.0.0.12022-05-02
CVE-2022-28572 [HIGH] CWE-78 CVE-2022-28572: Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status`
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function
nvd
CVE-2023-49044P3CRITICALCVSS 9.8v1.0.0.12023-11-27
CVE-2023-49044 [CRITICAL] CWE-787 CVE-2023-49044: Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary
Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form_fast_setting_wifi_set.
nvd
CVE-2023-49040P3CRITICALCVSS 9.8v1.0.0.12023-11-27
CVE-2023-49040 [CRITICAL] CWE-77 CVE-2023-49040: An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPw
An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function.
nvd
CVE-2023-49046P3CRITICALCVSS 9.8v1.0.0.12023-11-27
CVE-2023-49046 [CRITICAL] CWE-787 CVE-2023-49046: Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary
Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule.
nvd
CVE-2023-49042P3CRITICALCVSS 9.8v1.0.0.12023-11-27
CVE-2023-49042 [CRITICAL] CWE-787 CVE-2023-49042: Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary
Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi.
nvd
CVE-2022-45781P3HIGHCVSS 8.8≤ 1.0.0.1_29942023-11-14
CVE-2022-45781 [HIGH] CWE-787 CVE-2022-45781: Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbi
Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /goform/SetOnlineDevName.
nvd
CVE-2023-49047P3HIGHCVSS 7.5v1.0.0.12023-11-27
CVE-2023-49047 [HIGH] CWE-787 CVE-2023-49047: Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDev
Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.
nvd
CVE-2022-30040P3HIGHCVSS 7.5v1.0.0.1_28902022-05-11
CVE-2022-30040 [HIGH] CWE-787 CVE-2022-30040: Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In /
Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bin / tdhttpd in ubif file system, attackers can access http://ip/goform/SetSysTimeCfg, and by setting the ntpserve parameter, the stack buffer overflow can be caused to achieve the effect of router denial of service.
nvd
CVE-2025-63458P3HIGHCVSS 7.5v1.0.0.12025-10-31
CVE-2025-63458 [HIGH] CWE-121 CVE-2025-63458: Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the
Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd