Tendacn G3 Firmware vulnerabilities
28 known vulnerabilities affecting tendacn/g3_firmware.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH16
Vulnerabilities
Page 1 of 2
CVE-2021-27692P1CRITICALCVSS 9.8Exploitedv15.11.0.16\(9024\)_cnv15.11.0.17\(9502\)_cn2021-04-16
CVE-2021-27692 [CRITICAL] CWE-78 CVE-2021-27692: Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0
Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted "action/umountUSBPartition" request. This occurs because the "formSetUSBPartitionUmount" function executes the "doSystemCmd" function with untrusted input.
nvd
CVE-2021-27691P2CRITICALCVSS 9.8v15.11.0.16\(9024\)_cnv15.11.0.17\(9502\)_cn2021-04-16
CVE-2021-27691 [CRITICAL] CWE-78 CVE-2021-27691: Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876
Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" functi
nvd
CVE-2024-46628P2CRITICALCVSS 9.8v15.03.05.052024-09-26
CVE-2024-46628 [CRITICAL] CWE-78 CVE-2024-46628: Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulner
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.
nvd
CVE-2024-8224P2CRITICALCVSS 9.8v15.11.0.202024-08-27
CVE-2024-8224 [CRITICAL] CWE-121 CVE-2024-8224: A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.20. This issue
A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.20. This issue affects the function formSetDebugCfg of the file /goform/setDebugCfg. The manipulation of the argument enable/level/module leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and ma
nvd
CVE-2022-24168P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24168 [CRITICAL] CWE-77 CVE-2022-24168: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.
nvd
CVE-2022-24167P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24167 [CRITICAL] CWE-77 CVE-2022-24167: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.
nvd
CVE-2022-24171P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24171 [CRITICAL] CWE-77 CVE-2022-24171: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP parameters.
nvd
CVE-2022-24165P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24165 [CRITICAL] CWE-77 CVE-2022-24165: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.
nvd
CVE-2022-24170P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24170 [CRITICAL] CWE-77 CVE-2022-24170: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vulnerability allows attackers to execute arbitrary commands via the IPsecLocalNet and IPsecRemoteNet parameters.
nvd
CVE-2021-45990P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45990 [CRITICAL] CWE-77 CVE-2021-45990: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.
nvd
CVE-2021-45986P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45986 [CRITICAL] CWE-78 CVE-2021-45986: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.
nvd
CVE-2021-45987P2CRITICALCVSS 9.8v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45987 [CRITICAL] CWE-78 CVE-2021-45987: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerab
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.
nvd
CVE-2024-50852P2HIGHCVSS 8.8v15.11.0.202024-11-13
CVE-2024-50852 [HIGH] CWE-77 CVE-2024-50852: Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSe
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.
nvd
CVE-2024-50853P2HIGHCVSS 8.8v15.11.0.202024-11-13
CVE-2024-50853 [HIGH] CWE-77 CVE-2024-50853: Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSe
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.
nvd
CVE-2024-50854P3HIGHCVSS 8.8v15.11.0.202024-11-13
CVE-2024-50854 [HIGH] CWE-787 CVE-2024-50854: Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping func
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.
nvd
CVE-2021-45996P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2021-45996 [HIGH] CWE-787 CVE-2021-45996: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
nvd
CVE-2022-24172P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24172 [HIGH] CWE-787 CVE-2022-24172: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBindRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the addDhcpRules parameter.
nvd
CVE-2022-24164P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24164 [HIGH] CWE-787 CVE-2022-24164: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsHijackRule parameter.
nvd
CVE-2022-24169P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24169 [HIGH] CWE-787 CVE-2022-24169: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindAdd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRule parameter.
nvd
CVE-2022-24166P3HIGHCVSS 7.5v15.11.0.17\(9502\)_cn2022-02-04
CVE-2022-24166 [HIGH] CWE-787 CVE-2022-24166: Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the func
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the manualTime parameter.
nvd
1 / 2Next →