Tendacn Ac15 Firmware vulnerabilities
18 known vulnerabilities affecting tendacn/ac15_firmware.
Total CVEs
18
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH2
Vulnerabilities
Page 1 of 1
CVE-2022-40862CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40862 [CRITICAL] CWE-787 CVE-2022-40862: Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNa
Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting
nvd
CVE-2022-40853CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40853 [CRITICAL] CWE-787 CVE-2022-40853: Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_sett
Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set
nvd
CVE-2022-40865CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40865 [CRITICAL] CWE-787 CVE-2022-40865: Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSc
Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/
nvd
CVE-2022-40869CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40869 [CRITICAL] CWE-787 CVE-2022-40869: Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function from
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").
nvd
CVE-2022-40860CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40860 [CRITICAL] CWE-787 CVE-2022-40860: Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBan
Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList
nvd
CVE-2022-40864CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40864 [CRITICAL] CWE-787 CVE-2022-40864: Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setS
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet
nvd
CVE-2022-38326CRITICALCVSS 9.8v15.03.05.19_multi2022-09-15
CVE-2022-38326 [CRITICAL] CWE-120 CVE-2022-38326: Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.
nvd
CVE-2022-38325CRITICALCVSS 9.8v15.03.05.19_multi2022-09-15
CVE-2022-38325 [CRITICAL] CWE-120 CVE-2022-38325: Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.
nvd
CVE-2021-44352CRITICALCVSS 9.8v15.03.05.18_multi2021-12-03
CVE-2021-44352 [CRITICAL] CWE-787 CVE-2021-44352: A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via t
A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.
nvd
CVE-2020-13394CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13394 [CRITICAL] CWE-120 CVE-2020-13394: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetNetControlList list parameter for a
nvd
CVE-2020-13390CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13390 [CRITICAL] CWE-120 CVE-2020-13390: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/addressNat entrys and mitInterface par
nvd
CVE-2020-13393CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13393 [CRITICAL] CWE-120 CVE-2020-13393: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/saveParentControlInfo deviceId and tim
nvd
CVE-2020-13392CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13392 [CRITICAL] CWE-120 CVE-2020-13392: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/setcfm funcpara1 parameter for a POST
nvd
CVE-2020-13389CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13389 [CRITICAL] CWE-120 CVE-2020-13389: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/openSchedWifi schedStartTime and sched
nvd
CVE-2020-13391CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13391 [CRITICAL] CWE-120 CVE-2020-13391: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetSpeedWan speed_dir parameter for a
nvd
CVE-2018-16333HIGHCVSS 7.5v15.03.05.192018-09-02
CVE-2018-16333 [HIGH] CWE-119 CVE-2018-16333: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server. While processing the ssid parameter for a POST request, the value is directly used in a sprintf call to a local variabl
nvd
CVE-2018-14492HIGHCVSS 7.5≤ 15.03.05.19_cn2018-07-21
CVE-2018-14492 [HIGH] CWE-787 CVE-2018-14492: Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
nvd
CVE-2018-5767CRITICALCVSS 9.8PoCv15.03.1.162018-02-15
CVE-2018-5767 [CRITICAL] CWE-20 CVE-2018-5767: An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.
nvd