Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-45779EPSS 6%
Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.
Ac10 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-45513
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.
Fh451 Firmware
No fix yet
MEDIUM 6.5
CVE-2025-45514
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm.
Fh451 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-44899
There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, …
Rx3 Firmware
Mitigation only
MEDIUM 6.5
CVE-2025-44900
In Tenda RX3 V1.0br_V16.03.13.11 in the GetParentControlInfo function of the web url /goform/GetParentControlInfo, the manipulation of the parameter …
Rx3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-4368
A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetRouterStatus of the file /gofo…
Ac8 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-4357EPSS 15%
A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /gofo…
Rx3 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-45042
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
Ac9 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-44872
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. Th…
Ac9 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-44877
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This …
Ac9 Firmware
No fix yet
HIGH 8.2
CVE-2025-46633
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic b…
Rx2 Pro Firmware
No fix yet
HIGH 8.2
CVE-2025-46634
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker t…
Rx2 Pro Firmware
No fix yet
HIGH 7.1
CVE-2025-46635
An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.5
CVE-2025-46631EPSS 7%
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet acc…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.5
CVE-2025-46632
Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or …
Rx2 Pro Firmware
No fix yet
HIGH 8.8
CVE-2025-46625
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is auth…
Rx2 Pro Firmware
Mitigation only
HIGH 8.2
CVE-2025-46627
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the …
Rx2 Pro Firmware
No fix yet
HIGH 7.3
CVE-2025-46626
Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an …
Rx2 Pro Firmware
No fix yet
HIGH 7.3
CVE-2025-46628
Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.5
CVE-2025-46629
Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthor…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.5
CVE-2025-46630
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a r…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.3
CVE-2025-44865
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerabi…
W20e Firmware
No fix yet
MEDIUM 6.3
CVE-2025-44866
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerabil…
W20e Firmware
No fix yet
MEDIUM 6.3
CVE-2025-44867
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vu…
W20e Firmware
No fix yet
MEDIUM 6.3
CVE-2025-44864
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerabi…
W20e Firmware
No fix yet
HIGH 8.8
CVE-2025-4007
A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vulnerability is the function cgi…
W12 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-45429
In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to rem…
Ac9 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-45427
In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead…
Ac9 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-45428
In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which…
Ac9 Firmware
No fix yet
HIGH 8.8
CVE-2025-3820EPSS 11%
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysU…
W12 Firmware
No fix yet