Vulnerability index

Browse CVEs

1,740 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-45779EPSS 6% Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter. Ac10 Firmware No fix yet Fix from $2,3002025-05-12 CRITICAL 9.8 CVE-2025-45513 Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter. Fh451 Firmware No fix yet Fix from $2,3002025-05-09 MEDIUM 6.5 CVE-2025-45514 Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm. Fh451 Firmware No fix yet Fix from $1,6002025-05-07 CRITICAL 9.8 CVE-2025-44899 There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, … Rx3 Firmware Mitigation only Fix from $2,3002025-05-06 MEDIUM 6.5 CVE-2025-44900 In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the parameter … Rx3 Firmware Mitigation only Fix from $1,6002025-05-06 CRITICAL 9.8 CVE-2025-4368 A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetRouterStatus of the file /gofo… Ac8 Firmware Mitigation only Fix from $2,3002025-05-06 CRITICAL 9.8 CVE-2025-4357EPSS 15% A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /gofo… Rx3 Firmware No fix yet Fix from $2,3002025-05-06 CRITICAL 9.8 CVE-2025-45042 Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function. Ac9 Firmware No fix yet Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-44872 Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. Th… Ac9 Firmware No fix yet Fix from $2,3002025-05-02 CRITICAL 9.8 CVE-2025-44877 Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This … Ac9 Firmware No fix yet Fix from $2,3002025-05-02 HIGH 8.2 CVE-2025-46633 Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic b… Rx2 Pro Firmware No fix yet Fix from $1,9502025-05-01 HIGH 8.2 CVE-2025-46634 Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker t… Rx2 Pro Firmware No fix yet Fix from $1,9502025-05-01 HIGH 7.1 CVE-2025-46635 An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces… Rx2 Pro Firmware No fix yet Fix from $1,9502025-05-01 MEDIUM 6.5 CVE-2025-46631EPSS 7% Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet acc… Rx2 Pro Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-46632 Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or … Rx2 Pro Firmware No fix yet Fix from $1,6002025-05-01 HIGH 8.8 CVE-2025-46625 Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is auth… Rx2 Pro Firmware Mitigation only Fix from $1,9502025-05-01 HIGH 8.2 CVE-2025-46627 Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the … Rx2 Pro Firmware No fix yet Fix from $1,9502025-05-01 HIGH 7.3 CVE-2025-46626 Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an … Rx2 Pro Firmware No fix yet Fix from $1,9502025-05-01 HIGH 7.3 CVE-2025-46628 Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain… Rx2 Pro Firmware No fix yet Fix from $1,9502025-05-01 MEDIUM 6.5 CVE-2025-46629 Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthor… Rx2 Pro Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-46630 Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a r… Rx2 Pro Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44865 Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerabi… W20e Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44866 Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerabil… W20e Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44867 Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vu… W20e Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44864 Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerabi… W20e Firmware No fix yet Fix from $1,6002025-05-01 HIGH 8.8 CVE-2025-4007 A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vulnerability is the function cgi… W12 Firmware No fix yet Fix from $1,9502025-04-28 CRITICAL 9.8 CVE-2025-45429 In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to rem… Ac9 Firmware No fix yet Fix from $2,3002025-04-23 CRITICAL 9.8 CVE-2025-45427 In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead… Ac9 Firmware No fix yet Fix from $2,3002025-04-23 CRITICAL 9.8 CVE-2025-45428 In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which… Ac9 Firmware No fix yet Fix from $2,3002025-04-23 HIGH 8.8 CVE-2025-3820EPSS 11% A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysU… W12 Firmware No fix yet Fix from $1,9502025-04-19