Tendacn Ac18 Firmware vulnerabilities

18 known vulnerabilities affecting tendacn/ac18_firmware.

Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL16HIGH2

Vulnerabilities

Page 1 of 1
CVE-2024-33182CRITICALCVSS 9.8v15.03.3.102024-07-16
CVE-2024-33182 [CRITICAL] CWE-787 CVE-2024-33182: Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.
nvd
CVE-2024-33180CRITICALCVSS 9.8v15.03.3.102024-07-16
CVE-2024-33180 [CRITICAL] CWE-787 CVE-2024-33180: Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.
nvd
CVE-2022-40862CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40862 [CRITICAL] CWE-787 CVE-2022-40862: Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNa Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting
nvd
CVE-2022-40865CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40865 [CRITICAL] CWE-787 CVE-2022-40865: Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSc Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/
nvd
CVE-2022-40869CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40869 [CRITICAL] CWE-787 CVE-2022-40869: Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function from Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").
nvd
CVE-2022-40864CRITICALCVSS 9.8v15.03.05.192022-09-23
CVE-2022-40864 [CRITICAL] CWE-787 CVE-2022-40864: Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setS Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet
nvd
CVE-2022-38326CRITICALCVSS 9.8v15.03.05.19_multi2022-09-15
CVE-2022-38326 [CRITICAL] CWE-120 CVE-2022-38326: Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.
nvd
CVE-2022-38325CRITICALCVSS 9.8v15.03.05.19_multi2022-09-15
CVE-2022-38325 [CRITICAL] CWE-120 CVE-2022-38325: Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.
nvd
CVE-2022-31446CRITICALCVSS 9.8Exploitedv15.03.05.05v15.03.05.192022-06-14
CVE-2022-31446 [CRITICAL] CWE-78 CVE-2022-31446: Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (R Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.
nvd
CVE-2020-24987CRITICALCVSS 9.8≤ v15.03.05.05_en≤ v15.03.05.19\(6318\)_cn2020-09-04
CVE-2020-24987 [CRITICAL] CWE-287 CVE-2020-24987: Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a re Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authentication handling of vulnerable logincheck() function in /usr/lib/lua/ngx_authserver/ngx_wdas.lua file if the administrator UI Interface is set to "radius".
nvd
CVE-2020-13394CRITICALCVSS 9.8vv15.03.05.19\(6318\)2020-05-22
CVE-2020-13394 [CRITICAL] CWE-120 CVE-2020-13394: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetNetControlList list parameter for a
nvd
CVE-2020-13390CRITICALCVSS 9.8vv15.03.05.19\(6318\)2020-05-22
CVE-2020-13390 [CRITICAL] CWE-120 CVE-2020-13390: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/addressNat entrys and mitInterface par
nvd
CVE-2020-13393CRITICALCVSS 9.8vv15.03.05.19\(6318\)2020-05-22
CVE-2020-13393 [CRITICAL] CWE-120 CVE-2020-13393: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/saveParentControlInfo deviceId and tim
nvd
CVE-2020-13392CRITICALCVSS 9.8vv15.03.05.19\(6318\)2020-05-22
CVE-2020-13392 [CRITICAL] CWE-120 CVE-2020-13392: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/setcfm funcpara1 parameter for a POST
nvd
CVE-2020-13389CRITICALCVSS 9.8vv15.03.05.19\(6318\)2020-05-22
CVE-2020-13389 [CRITICAL] CWE-120 CVE-2020-13389: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/openSchedWifi schedStartTime and sched
nvd
CVE-2020-13391CRITICALCVSS 9.8vv15.03.05.19\(6318\)2020-05-22
CVE-2020-13391 [CRITICAL] CWE-120 CVE-2020-13391: An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, A An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetSpeedWan speed_dir parameter for a
nvd
CVE-2018-16333HIGHCVSS 7.5≤ 15.03.05.192018-09-02
CVE-2018-16333 [HIGH] CWE-119 CVE-2018-16333: An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_C An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server. While processing the ssid parameter for a POST request, the value is directly used in a sprintf call to a local variabl
nvd
CVE-2018-14492HIGHCVSS 7.5≤ 15.03.05.19\(6318\)_cn2018-07-21
CVE-2018-14492 [HIGH] CWE-787 CVE-2018-14492: Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_ Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
nvd