Tendacn G1 Firmware vulnerabilities
23 known vulnerabilities affecting tendacn/g1_firmware.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH13
Vulnerabilities
Page 1 of 2
CVE-2021-27692P1CRITICALCVSS 9.8Exploitedv15.11.0.16\(9024\)_cnv15.11.0.17\(9502\)_cn2021-04-16
CVE-2021-27692 [CRITICAL] CWE-78 CVE-2021-27692: Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0
Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted "action/umountUSBPartition" request. This occurs because the "formSetUSBPartitionUmount" function executes the "doSystemCmd" function with untrusted input.
nvd
CVE-2021-27691P2CRITICALCVSS 9.8v15.11.0.16\(9024\)_cnv15.11.0.17\(9502\)_cn2021-04-16
CVE-2021-27691 [CRITICAL] CWE-78 CVE-2021-27691: Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876
Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" functi
nvd
CVE-2022-24168P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24168 [CRITICAL] CWE-77 CVE-2022-24168: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.
nvd
CVE-2022-24167P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24167 [CRITICAL] CWE-77 CVE-2022-24167: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.
nvd
CVE-2022-24171P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24171 [CRITICAL] CWE-77 CVE-2022-24171: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP parameters.
nvd
CVE-2022-24165P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24165 [CRITICAL] CWE-77 CVE-2022-24165: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.
nvd
CVE-2022-24170P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24170 [CRITICAL] CWE-77 CVE-2022-24170: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vulnerability allows attackers to execute arbitrary commands via the IPsecLocalNet and IPsecRemoteNet parameters.
nvd
CVE-2021-45990P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45990 [CRITICAL] CWE-77 CVE-2021-45990: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.
nvd
CVE-2021-45986P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45986 [CRITICAL] CWE-78 CVE-2021-45986: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.
nvd
CVE-2021-45987P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45987 [CRITICAL] CWE-78 CVE-2021-45987: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.
nvd
CVE-2021-45996P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45996 [HIGH] CWE-787 CVE-2021-45996: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
nvd
CVE-2022-24172P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24172 [HIGH] CWE-787 CVE-2022-24172: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBindRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the addDhcpRules parameter.
nvd
CVE-2022-24164P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24164 [HIGH] CWE-787 CVE-2022-24164: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsHijackRule parameter.
nvd
CVE-2022-24169P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24169 [HIGH] CWE-787 CVE-2022-24169: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindAdd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRule parameter.
nvd
CVE-2022-24166P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24166 [HIGH] CWE-787 CVE-2022-24166: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the manualTime parameter.
nvd
CVE-2021-45993P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45993 [HIGH] CWE-787 CVE-2021-45993: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindModify. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRuleIP and IPMacBindRuleMac parameters.
nvd
CVE-2021-45997P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45997 [HIGH] CWE-787 CVE-2021-45997: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
nvd
CVE-2021-45989P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45989 [HIGH] CWE-787 CVE-2021-45989: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function guestWifiRuleRefresh. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qosGuestUpstream and qosGuestDownstream parameters.
nvd
CVE-2021-45988P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45988 [HIGH] CWE-787 CVE-2021-45988: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDnsForward. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsForwardRule parameter.
nvd
CVE-2021-45992P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45992 [HIGH] CWE-787 CVE-2021-45992: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetQvlanList. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qvlanName parameter.
nvd
1 / 2Next →