cbcvebase.

Tenda W15E Firmware vulnerabilities

31 known vulnerabilities affecting tenda/w15e_firmware.

Total CVEs
31
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH24MEDIUM4

Vulnerabilities

Page 2 of 2
CVE-2017-14514P3HIGHCVSS 7.5≤ v15.11.0.13_cn2017-09-17
CVE-2017-14514 [HIGH] CWE-22 CVE-2017-14514: Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencryp Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a crafted URL.
nvd
CVE-2022-42053P3HIGHCVSS 7.8v15.11.0.10\(1576\)2022-11-15
CVE-2022-42053 [HIGH] CWE-78 CVE-2022-42053: Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vul Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.
nvd
CVE-2022-41396P3HIGHCVSS 7.8v15.11.0.10\(1576\)2022-11-15
CVE-2022-41396 [HIGH] CWE-78 CVE-2022-41396: Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command inject Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.
nvd
CVE-2023-27062P3HIGHCVSS 7.5v15.11.0.142023-03-13
CVE-2023-27062 [HIGH] CWE-120 CVE-2023-27062: Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2022-42060P3HIGHCVSS 7.5v15.11.0.10\(1576\)2022-11-15
CVE-2022-42060 [HIGH] CWE-787 CVE-2022-42060: Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via th Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
nvd
CVE-2023-27065P3HIGHCVSS 7.5v15.11.0.142023-03-13
CVE-2023-27065 [HIGH] CWE-120 CVE-2023-27065: Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2023-27064P3HIGHCVSS 7.5v15.11.0.142023-03-13
CVE-2023-27064 [HIGH] CWE-120 CVE-2023-27064: Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2022-40845P3MEDIUMCVSS 6.5v15.11.0.10\(1576\)2022-11-15
CVE-2022-40845 [MEDIUM] CWE-425 CVE-2022-40845: The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerabil The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information which they're not explicitly authorized to have.
nvd
CVE-2017-14515P3HIGHCVSS 7.5≤ v15.11.0.13_cn2017-09-17
CVE-2017-14515 [HIGH] CWE-119 CVE-2017-14515: Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service (temporary HTTP outage and forced logout) via unspecified vectors.
nvd
CVE-2022-40844P4MEDIUMCVSS 5.4v15.11.0.10\(1576\)2022-11-15
CVE-2022-40844 [MEDIUM] CWE-79 CVE-2022-40844: In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL body.
nvd
CVE-2022-40846P4MEDIUMCVSS 4.8v15.11.0.10\(1576\)2022-11-15
CVE-2022-40846 [MEDIUM] CWE-79 CVE-2022-40846: In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerabi In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.
nvd
Tenda W15E Firmware vulnerabilities | cvebase