Tendacn Ac15 Firmware vulnerabilities

18 known vulnerabilities affecting tendacn/ac15_firmware.

Total CVEs
18
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH2

Vulnerabilities

Page 1 of 1
CVE-2022-40862CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40862 [CRITICAL] CWE-787 CVE-2022-40862: Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNa Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting
nvd
CVE-2022-40853CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40853 [CRITICAL] CWE-787 CVE-2022-40853: Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_sett Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set
nvd
CVE-2022-40865CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40865 [CRITICAL] CWE-787 CVE-2022-40865: Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSc Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/
nvd
CVE-2022-40869CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40869 [CRITICAL] CWE-787 CVE-2022-40869: Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function from Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").
nvd
CVE-2022-40860CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40860 [CRITICAL] CWE-787 CVE-2022-40860: Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBan Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList
nvd
CVE-2022-40864CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40864 [CRITICAL] CWE-787 CVE-2022-40864: Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setS Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet
nvd
CVE-2022-38326CRITICALCVSS 9.8v15.03.05.19_multi2022-09-15
CVE-2022-38326 [CRITICAL] CWE-120 CVE-2022-38326: Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.
nvd
CVE-2022-38325CRITICALCVSS 9.8v15.03.05.19_multi2022-09-15
CVE-2022-38325 [CRITICAL] CWE-120 CVE-2022-38325: Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.
nvd
CVE-2021-44352CRITICALCVSS 9.8v15.03.05.18_multi2021-12-03
CVE-2021-44352 [CRITICAL] CWE-787 CVE-2021-44352: A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via t A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.
nvd
CVE-2020-13394CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13394 [CRITICAL] CWE-120 CVE-2020-13394: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetNetControlList list parameter for a
nvd
CVE-2020-13390CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13390 [CRITICAL] CWE-120 CVE-2020-13390: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/addressNat entrys and mitInterface par
nvd
CVE-2020-13393CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13393 [CRITICAL] CWE-120 CVE-2020-13393: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/saveParentControlInfo deviceId and tim
nvd
CVE-2020-13392CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13392 [CRITICAL] CWE-120 CVE-2020-13392: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/setcfm funcpara1 parameter for a POST
nvd
CVE-2020-13389CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13389 [CRITICAL] CWE-120 CVE-2020-13389: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/openSchedWifi schedStartTime and sched
nvd
CVE-2020-13391CRITICALCVSS 9.8vv15.03.05.19_multi_td012020-05-22
CVE-2020-13391 [CRITICAL] CWE-120 CVE-2020-13391: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetSpeedWan speed_dir parameter for a
nvd
CVE-2018-16333HIGHCVSS 7.5v15.03.05.192018-09-02
CVE-2018-16333 [HIGH] CWE-119 CVE-2018-16333: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server. While processing the ssid parameter for a POST request, the value is directly used in a sprintf call to a local variabl
nvd
CVE-2018-14492HIGHCVSS 7.5≤ 15.03.05.19_cn2018-07-21
CVE-2018-14492 [HIGH] CWE-787 CVE-2018-14492: Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_ Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
nvd
CVE-2018-5767CRITICALCVSS 9.8PoCv15.03.1.162018-02-15
CVE-2018-5767 [CRITICAL] CWE-20 CVE-2018-5767: An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.
nvd