cbcvebase.

Tenda Ax1803 Firmware vulnerabilities

60 known vulnerabilities affecting tenda/ax1803_firmware.

Total CVEs
60
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL31HIGH27MEDIUM2

Vulnerabilities

Page 3 of 3
CVE-2025-63457P3HIGHCVSS 7.5v1.0.0.12025-11-10
CVE-2025-63457 [HIGH] CWE-787 CVE-2025-63457: Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the su Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-70648P3HIGHCVSS 7.5v1.0.0.12026-01-21
CVE-2025-70648 [HIGH] CWE-121 CVE-2025-70648: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-70646P3HIGHCVSS 7.5v1.0.0.12026-01-21
CVE-2025-70646 [HIGH] CWE-121 CVE-2025-70646: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the su Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2025-70651P3HIGHCVSS 7.5v1.0.0.12026-01-21
CVE-2025-70651 [HIGH] CWE-121 CVE-2025-70651: Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_ Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2022-37823P3HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37823 [HIGH] CWE-787 CVE-2022-37823: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the funct Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSer.
nvd
CVE-2022-37818P3HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37818 [HIGH] CWE-787 CVE-2022-37818: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter at the funct Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
nvd
CVE-2025-63456P3HIGHCVSS 7.5v1.0.0.12025-11-10
CVE-2025-63456 [HIGH] CWE-787 CVE-2025-63456: Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetS Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2022-37824P3HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37824 [HIGH] CWE-787 CVE-2022-37824: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic.
nvd
CVE-2022-37820P3HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37820 [HIGH] CWE-787 CVE-2022-37820: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the fun Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysToolDDNS.
nvd
CVE-2022-37819P3HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37819 [HIGH] CWE-787 CVE-2022-37819: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the f Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the function fromSetSysTime.
nvd
CVE-2022-37821P3HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37821 [HIGH] CWE-787 CVE-2022-37821: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in t Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in the function formSetProvince.
nvd
CVE-2022-37817P3HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37817 [HIGH] CWE-787 CVE-2022-37817: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind. Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.
nvd
CVE-2022-37822P3HIGHCVSS 7.8v1.0.0.12022-08-25
CVE-2022-37822 [HIGH] CWE-787 CVE-2022-37822: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic.
nvd
CVE-2023-48111P3HIGHCVSS 7.5v1.0.0.12023-11-20
CVE-2023-48111 [HIGH] CWE-787 CVE-2023-48111: Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the funct Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack
nvd
CVE-2022-40875P3HIGHCVSS 7.5v1.0.0.12022-10-27
CVE-2022-40875 [HIGH] CWE-787 CVE-2022-40875: Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.
nvd
CVE-2022-40874P3HIGHCVSS 7.5v1.0.0.12022-10-27
CVE-2022-40874 [HIGH] CWE-787 CVE-2022-40874: Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentContro Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.
nvd
CVE-2023-48110P3HIGHCVSS 7.5v1.0.0.12023-11-20
CVE-2023-48110 [HIGH] CWE-787 CVE-2023-48110: Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the functi Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack
nvd
CVE-2023-48109P3HIGHCVSS 7.5v1.0.0.12023-11-20
CVE-2023-48109 [HIGH] CWE-787 CVE-2023-48109: Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the fu Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack
nvd
CVE-2022-42086P4MEDIUMCVSS 6.5v1.0.0.1_2994_cn_zgyd01_42022-10-12
CVE-2022-42086 [MEDIUM] CWE-352 CVE-2022-42086: Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery ( Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.
nvd
CVE-2022-42087P4MEDIUMCVSS 6.5v1.0.0.1_2994_cn_zgyd01_42022-10-12
CVE-2022-42087 [MEDIUM] CWE-352 CVE-2022-42087: Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery ( Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
nvd