Vulnerability index

Browse CVEs

1,740 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ac10 Firmware CRITICAL 9.8
CVE-2025-45779EPSS 6%

Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.

No fix yet
Fix from $2,300 2025-05-12
Fh451 Firmware CRITICAL 9.8
CVE-2025-45513

Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.

No fix yet
Fix from $2,300 2025-05-09
Fh451 Firmware MEDIUM 6.5
CVE-2025-45514

Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.

No fix yet
Fix from $1,600 2025-05-07
Rx3 Firmware CRITICAL 9.8
CVE-2025-44899

There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, …

Mitigation only
Fix from $2,300 2025-05-06
Rx3 Firmware MEDIUM 6.5
CVE-2025-44900

In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the parameter …

Mitigation only
Fix from $1,600 2025-05-06
Ac8 Firmware CRITICAL 9.8
CVE-2025-4368

A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetRouterStatus of the file /gofo…

Mitigation only
Fix from $2,300 2025-05-06
Rx3 Firmware CRITICAL 9.8
CVE-2025-4357EPSS 15%

A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /gofo…

No fix yet
Fix from $2,300 2025-05-06
Ac9 Firmware CRITICAL 9.8
CVE-2025-45042

Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.

No fix yet
Fix from $2,300 2025-05-05
Ac9 Firmware CRITICAL 9.8
CVE-2025-44872

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. Th…

No fix yet
Fix from $2,300 2025-05-02
Ac9 Firmware CRITICAL 9.8
CVE-2025-44877

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This …

No fix yet
Fix from $2,300 2025-05-02
Rx2 Pro Firmware HIGH 8.2
CVE-2025-46633

Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic b…

No fix yet
Fix from $1,950 2025-05-01
Rx2 Pro Firmware HIGH 8.2
CVE-2025-46634

Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker t…

No fix yet
Fix from $1,950 2025-05-01
Rx2 Pro Firmware HIGH 7.1
CVE-2025-46635

An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces…

No fix yet
Fix from $1,950 2025-05-01
Rx2 Pro Firmware MEDIUM 6.5
CVE-2025-46631EPSS 7%

Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet acc…

No fix yet
Fix from $1,600 2025-05-01
Rx2 Pro Firmware MEDIUM 6.5
CVE-2025-46632

Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or …

No fix yet
Fix from $1,600 2025-05-01
Rx2 Pro Firmware HIGH 8.8
CVE-2025-46625

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is auth…

Mitigation only
Fix from $1,950 2025-05-01
Rx2 Pro Firmware HIGH 8.2
CVE-2025-46627

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the …

No fix yet
Fix from $1,950 2025-05-01
Rx2 Pro Firmware HIGH 7.3
CVE-2025-46626

Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an …

No fix yet
Fix from $1,950 2025-05-01
Rx2 Pro Firmware HIGH 7.3
CVE-2025-46628

Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain…

No fix yet
Fix from $1,950 2025-05-01
Rx2 Pro Firmware MEDIUM 6.5
CVE-2025-46629

Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthor…

No fix yet
Fix from $1,600 2025-05-01
Rx2 Pro Firmware MEDIUM 6.5
CVE-2025-46630

Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a r…

No fix yet
Fix from $1,600 2025-05-01
W20e Firmware MEDIUM 6.3
CVE-2025-44865

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerabi…

No fix yet
Fix from $1,600 2025-05-01
W20e Firmware MEDIUM 6.3
CVE-2025-44866

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerabil…

No fix yet
Fix from $1,600 2025-05-01
W20e Firmware MEDIUM 6.3
CVE-2025-44867

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vu…

No fix yet
Fix from $1,600 2025-05-01
W20e Firmware MEDIUM 6.3
CVE-2025-44864

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerabi…

No fix yet
Fix from $1,600 2025-05-01
W12 Firmware HIGH 8.8
CVE-2025-4007

A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vulnerability is the function cgi…

No fix yet
Fix from $1,950 2025-04-28
Ac9 Firmware CRITICAL 9.8
CVE-2025-45429

In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to rem…

No fix yet
Fix from $2,300 2025-04-23
Ac9 Firmware CRITICAL 9.8
CVE-2025-45427

In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead…

No fix yet
Fix from $2,300 2025-04-23
Ac9 Firmware CRITICAL 9.8
CVE-2025-45428

In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which…

No fix yet
Fix from $2,300 2025-04-23
W12 Firmware HIGH 8.8
CVE-2025-3820EPSS 11%

A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysU…

No fix yet
Fix from $1,950 2025-04-19