Tendacn G1 Firmware vulnerabilities

23 known vulnerabilities affecting tendacn/g1_firmware.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH13

Vulnerabilities

Page 1 of 2
CVE-2022-24168CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24168 [CRITICAL] CWE-77 CVE-2022-24168: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.
nvd
CVE-2022-24167CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24167 [CRITICAL] CWE-77 CVE-2022-24167: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.
nvd
CVE-2021-45990CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45990 [CRITICAL] CWE-77 CVE-2021-45990: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.
nvd
CVE-2022-24171CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24171 [CRITICAL] CWE-77 CVE-2022-24171: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP parameters.
nvd
CVE-2022-24165CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24165 [CRITICAL] CWE-77 CVE-2022-24165: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.
nvd
CVE-2021-45986CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45986 [CRITICAL] CWE-78 CVE-2021-45986: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.
nvd
CVE-2022-24170CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24170 [CRITICAL] CWE-77 CVE-2022-24170: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vulnerability allows attackers to execute arbitrary commands via the IPsecLocalNet and IPsecRemoteNet parameters.
nvd
CVE-2021-45987CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45987 [CRITICAL] CWE-78 CVE-2021-45987: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.
nvd
CVE-2021-45988HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45988 [HIGH] CWE-787 CVE-2021-45988: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDnsForward. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsForwardRule parameter.
nvd
CVE-2022-24172HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24172 [HIGH] CWE-787 CVE-2022-24172: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBindRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the addDhcpRules parameter.
nvd
CVE-2021-45992HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45992 [HIGH] CWE-787 CVE-2021-45992: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetQvlanList. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qvlanName parameter.
nvd
CVE-2021-45993HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45993 [HIGH] CWE-787 CVE-2021-45993: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindModify. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRuleIP and IPMacBindRuleMac parameters.
nvd
CVE-2022-24164HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24164 [HIGH] CWE-787 CVE-2022-24164: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsHijackRule parameter.
nvd
CVE-2021-45994HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45994 [HIGH] CWE-787 CVE-2021-45994: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formDelDhcpRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the delDhcpIndex parameter.
nvd
CVE-2021-45991HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45991 [HIGH] CWE-787 CVE-2021-45991: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddVpnUsers. This vulnerability allows attackers to cause a Denial of Service (DoS) via the vpnUsers parameter.
nvd
CVE-2021-45995HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45995 [HIGH] CWE-787 CVE-2021-45995: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetStaticRoute. This vulnerability allows attackers to cause a Denial of Service (DoS) via the staticRouteNet, staticRouteMask, and staticRouteGateway parameters.
nvd
CVE-2022-24169HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24169 [HIGH] CWE-787 CVE-2022-24169: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindAdd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRule parameter.
nvd
CVE-2021-45996HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45996 [HIGH] CWE-787 CVE-2021-45996: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
nvd
CVE-2021-45997HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45997 [HIGH] CWE-787 CVE-2021-45997: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
nvd
CVE-2022-24166HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24166 [HIGH] CWE-787 CVE-2022-24166: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the manualTime parameter.
nvd