Tenda Ax1803 Firmware vulnerabilities
60 known vulnerabilities affecting tenda/ax1803_firmware.
Total CVEs
60
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL31HIGH27MEDIUM2
Vulnerabilities
Page 3 of 3
CVE-2023-48110HIGHCVSS 7.5v1.0.0.12023-11-20
CVE-2023-48110 [HIGH] CWE-787 CVE-2023-48110: Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the functi
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack
nvd
CVE-2023-48111HIGHCVSS 7.5v1.0.0.12023-11-20
CVE-2023-48111 [HIGH] CWE-787 CVE-2023-48111: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the funct
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack
nvd
CVE-2022-45781HIGHCVSS 8.8≤ 1.0.0.1_29942023-11-14
CVE-2022-45781 [HIGH] CWE-787 CVE-2022-45781: Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbi
Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /goform/SetOnlineDevName.
nvd
CVE-2022-40876CRITICALCVSS 9.8v1.0.0.12022-10-27
CVE-2022-40876 [CRITICAL] CWE-787 CVE-2022-40876: In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed,
In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).
nvd
CVE-2022-40875HIGHCVSS 7.5v1.0.0.12022-10-27
CVE-2022-40875 [HIGH] CWE-787 CVE-2022-40875: Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.
nvd
CVE-2022-40874HIGHCVSS 7.5v1.0.0.12022-10-27
CVE-2022-40874 [HIGH] CWE-787 CVE-2022-40874: Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentContro
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.
nvd
CVE-2022-42086MEDIUMCVSS 6.5v1.0.0.1_2994_cn_zgyd01_42022-10-12
CVE-2022-42086 [MEDIUM] CWE-352 CVE-2022-42086: Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (
Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.
nvd
CVE-2022-42087MEDIUMCVSS 6.5v1.0.0.1_2994_cn_zgyd01_42022-10-12
CVE-2022-42087 [MEDIUM] CWE-352 CVE-2022-42087: Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (
Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
nvd
CVE-2022-37817HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37817 [HIGH] CWE-787 CVE-2022-37817: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.
nvd
CVE-2022-37818HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37818 [HIGH] CWE-787 CVE-2022-37818: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter at the funct
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
nvd
CVE-2022-37824HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37824 [HIGH] CWE-787 CVE-2022-37824: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic.
nvd
CVE-2022-37820HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37820 [HIGH] CWE-787 CVE-2022-37820: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the fun
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysToolDDNS.
nvd
CVE-2022-37823HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37823 [HIGH] CWE-787 CVE-2022-37823: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the funct
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSer.
nvd
CVE-2022-37819HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37819 [HIGH] CWE-787 CVE-2022-37819: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the f
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the function fromSetSysTime.
nvd
CVE-2022-37821HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37821 [HIGH] CWE-787 CVE-2022-37821: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in t
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in the function formSetProvince.
nvd
CVE-2022-37822HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37822 [HIGH] CWE-787 CVE-2022-37822: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic.
nvd
CVE-2022-34595CRITICALCVSS 9.8v1.0.0.1_28902022-07-06
CVE-2022-34595 [CRITICAL] CWE-78 CVE-2022-34595: Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the funct
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.
nvd
CVE-2022-34596CRITICALCVSS 9.8v1.0.0.1_28902022-07-06
CVE-2022-34596 [CRITICAL] CWE-78 CVE-2022-34596: Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the funct
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
nvd
CVE-2022-30040HIGHCVSS 7.5v1.0.0.1_28902022-05-11
CVE-2022-30040 [HIGH] CWE-787 CVE-2022-30040: Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In /
Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bin / tdhttpd in ubif file system, attackers can access http://ip/goform/SetSysTimeCfg, and by setting the ntpserve parameter, the stack buffer overflow can be caused to achieve the effect of router denial of service.
nvd
CVE-2022-28572HIGHCVSS 8.8v1.0.0.12022-05-02
CVE-2022-28572 [HIGH] CWE-78 CVE-2022-28572: Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status`
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function
nvd
← Previous3 / 3