Tenda Ax1806 Firmware vulnerabilities
61 known vulnerabilities affecting tenda/ax1806_firmware.
Total CVEs
61
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL20HIGH39MEDIUM2
Vulnerabilities
Page 1 of 4
CVE-2024-4238P2HIGHCVSS 8.8v1.0.0.12024-04-26
CVE-2024-4238 [HIGH] CWE-121 CVE-2024-4238: A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this
A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may b
nvd
CVE-2024-4239P2HIGHCVSS 8.8v1.0.0.12024-04-26
CVE-2024-4239 [HIGH] CWE-121 CVE-2024-4239: A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue
A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VD
nvd
CVE-2024-4237P2HIGHCVSS 8.8v1.0.0.12024-04-26
CVE-2024-4237 [HIGH] CWE-121 CVE-2024-4237: A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is th
A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. T
nvd
CVE-2022-32032P2CRITICALCVSS 9.8v1.0.0.12022-07-01
CVE-2022-32032 [CRITICAL] CWE-787 CVE-2022-32032: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the
Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the deviceList parameter in the function formAddMacfilterRule.
nvd
CVE-2022-34597P2CRITICALCVSS 9.8v1.0.0.12022-07-06
CVE-2022-34597 [CRITICAL] CWE-78 CVE-2022-34597: Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function W
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
nvd
CVE-2024-44555P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44555 [CRITICAL] CWE-787 CVE-2024-44555: Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function set
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.
nvd
CVE-2024-44551P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44551 [CRITICAL] CWE-787 CVE-2024-44551: Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function for
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
nvd
CVE-2024-44550P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44550 [CRITICAL] CWE-787 CVE-2024-44550: Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function f
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.
nvd
CVE-2024-44558P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44558 [CRITICAL] CWE-787 CVE-2024-44558: Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function s
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.
nvd
CVE-2024-44565P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44565 [CRITICAL] CWE-787 CVE-2024-44565: Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fa
Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.
nvd
CVE-2024-40416P2CRITICALCVSS 9.8v1.0.0.12024-07-15
CVE-2024-40416 [CRITICAL] CWE-787 CVE-2024-40416: A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 fir
A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.
nvd
CVE-2024-40414P2CRITICALCVSS 9.8v1.0.0.12024-07-15
CVE-2024-40414 [CRITICAL] CWE-787 CVE-2024-40414: A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmw
A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.
nvd
CVE-2024-40415P2CRITICALCVSS 9.8v1.0.0.12024-07-15
CVE-2024-40415 [CRITICAL] CWE-787 CVE-2024-40415: A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmw
A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.
nvd
CVE-2024-35580P2CRITICALCVSS 9.8v1.0.0.12024-05-20
CVE-2024-35580 [CRITICAL] CWE-121 CVE-2024-35580: Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function f
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
nvd
CVE-2024-44556P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44556 [CRITICAL] CWE-787 CVE-2024-44556: Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the functi
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
nvd
CVE-2024-44552P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44552 [CRITICAL] CWE-787 CVE-2024-44552: Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the functi
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.
nvd
CVE-2024-44553P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44553 [CRITICAL] CWE-787 CVE-2024-44553: Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function form
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
nvd
CVE-2024-44557P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44557 [CRITICAL] CWE-787 CVE-2024-44557: Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setI
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.
nvd
CVE-2024-44563P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44563 [CRITICAL] CWE-787 CVE-2024-44563: Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setI
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
nvd
CVE-2024-44549P2CRITICALCVSS 9.8v1.0.0.12024-08-26
CVE-2024-44549 [CRITICAL] CWE-787 CVE-2024-44549: Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function form
Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
nvd
1 / 4Next →