Tendacn G3 Firmware vulnerabilities
28 known vulnerabilities affecting tendacn/g3_firmware.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH17
Vulnerabilities
Page 1 of 2
CVE-2024-50852HIGHCVSS 8.8v15.11.0.202024-11-13
CVE-2024-50852 [HIGH] CWE-77 CVE-2024-50852: Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSe
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.
nvd
CVE-2024-50853HIGHCVSS 8.8v15.11.0.202024-11-13
CVE-2024-50853 [HIGH] CWE-77 CVE-2024-50853: Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSe
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.
nvd
CVE-2024-50854HIGHCVSS 8.8v15.11.0.202024-11-13
CVE-2024-50854 [HIGH] CWE-787 CVE-2024-50854: Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping func
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.
nvd
CVE-2024-46628CRITICALCVSS 9.8v15.03.05.052024-09-26
CVE-2024-46628 [CRITICAL] CWE-78 CVE-2024-46628: Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulner
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.
nvd
CVE-2024-8224HIGHCVSS 8.7v15.11.0.202024-08-27
CVE-2024-8224 [HIGH] CWE-121 CVE-2024-8224: A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.20. This issue
A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.20. This issue affects the function formSetDebugCfg of the file /goform/setDebugCfg. The manipulation of the argument enable/level/module leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be
nvd
CVE-2022-24168CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24168 [CRITICAL] CWE-77 CVE-2022-24168: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.
nvd
CVE-2022-24167CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24167 [CRITICAL] CWE-77 CVE-2022-24167: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.
nvd
CVE-2021-45990CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45990 [CRITICAL] CWE-77 CVE-2021-45990: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.
nvd
CVE-2022-24171CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24171 [CRITICAL] CWE-77 CVE-2022-24171: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP parameters.
nvd
CVE-2022-24165CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24165 [CRITICAL] CWE-77 CVE-2022-24165: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.
nvd
CVE-2021-45986CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45986 [CRITICAL] CWE-78 CVE-2021-45986: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.
nvd
CVE-2022-24170CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24170 [CRITICAL] CWE-77 CVE-2022-24170: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vulnerability allows attackers to execute arbitrary commands via the IPsecLocalNet and IPsecRemoteNet parameters.
nvd
CVE-2021-45987CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45987 [CRITICAL] CWE-78 CVE-2021-45987: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.
nvd
CVE-2021-45988HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45988 [HIGH] CWE-787 CVE-2021-45988: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDnsForward. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsForwardRule parameter.
nvd
CVE-2022-24172HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24172 [HIGH] CWE-787 CVE-2022-24172: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBindRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the addDhcpRules parameter.
nvd
CVE-2021-45992HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45992 [HIGH] CWE-787 CVE-2021-45992: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetQvlanList. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qvlanName parameter.
nvd
CVE-2021-45993HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45993 [HIGH] CWE-787 CVE-2021-45993: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindModify. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRuleIP and IPMacBindRuleMac parameters.
nvd
CVE-2022-24164HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24164 [HIGH] CWE-787 CVE-2022-24164: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsHijackRule parameter.
nvd
CVE-2021-45994HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45994 [HIGH] CWE-787 CVE-2021-45994: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formDelDhcpRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the delDhcpIndex parameter.
nvd
CVE-2021-45991HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45991 [HIGH] CWE-787 CVE-2021-45991: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddVpnUsers. This vulnerability allows attackers to cause a Denial of Service (DoS) via the vpnUsers parameter.
nvd
1 / 2Next →