cbcvebase.

Tenda Ax1806 Firmware vulnerabilities

61 known vulnerabilities affecting tenda/ax1806_firmware.

Total CVEs
61
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL20HIGH39MEDIUM2

Vulnerabilities

Page 3 of 4
CVE-2025-70644P3HIGHCVSS 7.5v1.0.0.12026-01-21
CVE-2025-70644 [HIGH] CWE-121 CVE-2025-70644: Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_6 Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2022-32033P3HIGHCVSS 7.5v1.0.0.12022-07-01
CVE-2022-32033 [HIGH] CWE-787 CVE-2022-32033: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the function formSetVirtualSer. Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the function formSetVirtualSer.
nvd
CVE-2022-25566P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25566 [HIGH] CWE-787 CVE-2022-25566: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlIn Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.
nvd
CVE-2022-25553P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25553 [HIGH] CWE-787 CVE-2022-25553: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsPwd parameter.
nvd
CVE-2022-25549P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25549 [HIGH] CWE-787 CVE-2022-25549: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsEn parameter.
nvd
CVE-2022-25555P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25555 [HIGH] CWE-787 CVE-2022-25555: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. Thi Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ntpServer parameter.
nvd
CVE-2022-25558P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25558 [HIGH] CWE-787 CVE-2022-25558: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetProvince. Th Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetProvince. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ProvinceCode parameter.
nvd
CVE-2022-25552P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25552 [HIGH] CWE-787 CVE-2022-25552: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function form_fast_setting_w Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.
nvd
CVE-2022-25550P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25550 [HIGH] CWE-787 CVE-2022-25550: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlIn Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceName parameter.
nvd
CVE-2022-25554P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25554 [HIGH] CWE-787 CVE-2022-25554: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlIn Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceId parameter.
nvd
CVE-2022-25551P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25551 [HIGH] CWE-787 CVE-2022-25551: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ddnsDomain parameter.
nvd
CVE-2022-25548P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25548 [HIGH] CWE-787 CVE-2022-25548: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. Thi Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the serverName parameter.
nvd
CVE-2022-28972P3HIGHCVSS 7.5v1.0.0.12022-05-06
CVE-2022-28972 [HIGH] CWE-787 CVE-2022-28972: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the f Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS).
nvd
CVE-2022-28971P3HIGHCVSS 7.5v1.0.0.12022-05-06
CVE-2022-28971 [HIGH] CWE-787 CVE-2022-28971: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the funct Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetIpMacBind. This vulnerability allows attackers to cause a Denial of Service (DoS).
nvd
CVE-2022-28973P3HIGHCVSS 7.5v1.0.0.12022-05-06
CVE-2022-28973 [HIGH] CWE-787 CVE-2022-28973: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the fun Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the function fromAdvSetMacMtuWan. This vulnerability allows attackers to cause a Denial of Service (DoS).
nvd
CVE-2022-28969P3HIGHCVSS 7.5v1.0.0.12022-05-06
CVE-2022-28969 [HIGH] CWE-787 CVE-2022-28969: Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS).
nvd
CVE-2022-25557P3HIGHCVSS 7.5v1.0.0.12022-03-10
CVE-2022-25557 [HIGH] CWE-787 CVE-2022-25557: Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow in the function saveParentControlInf Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the urls parameter.
nvd
CVE-2022-28970P3HIGHCVSS 7.5v1.0.0.12022-05-06
CVE-2022-28970 [HIGH] CWE-787 CVE-2022-28970: Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the functio Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS).
nvd
CVE-2024-41492P3HIGHCVSS 7.5v1.0.0.12024-07-19
CVE-2024-41492 [HIGH] CWE-121 CVE-2024-41492: A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
nvd
CVE-2024-40417P4MEDIUMCVSS 6.5v1.0.0.12024-07-10
CVE-2024-40417 [MEDIUM] CWE-121 CVE-2024-40417: A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetReb A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow.
nvd
Tenda Ax1806 Firmware vulnerabilities | cvebase