Vulnerability index

Browse CVEs

1,819 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rx3 Firmware HIGH 8.8
CVE-2026-2186

A vulnerability has been found in Tenda RX3 16.03.13.11. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulatio…

No fix yet
Fix from $1,950 2026-02-08
Rx3 Firmware HIGH 8.8
CVE-2026-2187

A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performi…

No fix yet
Fix from $1,950 2026-02-08
Rx3 Firmware HIGH 8.8
CVE-2026-2180

A vulnerability was identified in Tenda RX3 16.03.13.11. Affected is an unknown function of the file /goform/fast_setting_wifi_set. Such manipulation…

No fix yet
Fix from $1,950 2026-02-08
Rx3 Firmware HIGH 8.8
CVE-2026-2181

A security flaw has been discovered in Tenda RX3 16.03.13.11. Affected by this vulnerability is an unknown functionality of the file /goform/openSche…

No fix yet
Fix from $1,950 2026-02-08
Ac21 Firmware HIGH 7.5
CVE-2026-2148

A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the compo…

No fix yet
Fix from $1,950 2026-02-08
Ac21 Firmware MEDIUM 5.3
CVE-2026-2147

A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Mana…

No fix yet
Fix from $1,600 2026-02-08
Tx9 Firmware HIGH 8.8
CVE-2026-2140

A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilt…

Fix: after 22.03.02.10
Fix from $1,950 2026-02-08
Tx9 Firmware HIGH 8.8
CVE-2026-2139

A vulnerability was determined in Tenda TX9 up to 22.03.02.10_multi. Affected by this vulnerability is the function sub_432580 of the file /goform/fa…

Fix: after 22.03.02.10
Fix from $1,950 2026-02-08
Tx9 Firmware HIGH 8.8
CVE-2026-2138

A vulnerability was found in Tenda TX9 up to 22.03.02.10_multi. Affected is the function sub_42D03C of the file /goform/SetStaticRouteCfg. The manipu…

Fix: after 22.03.02.10
Fix from $1,950 2026-02-08
Tx3 Firmware HIGH 8.8
CVE-2026-2137

A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /goform/SetIpMacBind. The manipulat…

Fix: after 16.03.13.11
Fix from $1,950 2026-02-08
G300 F Firmware HIGH 8.8
CVE-2026-25857

Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetW…

Fix: after 16.01.14.2
Fix from $1,950 2026-02-07
Ac7 Firmware MEDIUM 6.5
CVE-2026-24434

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management …

Fix: after 03.03.03.01
Fix from $1,600 2026-02-03
Ac7 Firmware MEDIUM 5.9
CVE-2026-24441

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path atta…

Fix: after 03.03.03.01
Fix from $1,600 2026-02-03
Ac7 Firmware MEDIUM 6.1
CVE-2026-24426

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User…

Fix: after 03.03.03.01
Fix from $1,600 2026-02-03
Ac7 Firmware MEDIUM 5.5
CVE-2026-24427

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose sensitive information in web management responses. Administrative credentials, i…

Fix: after 03.03.03.01
Fix from $1,600 2026-02-03
Hg10 Firmware HIGH 7.3
CVE-2026-1689

A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the fil…

No fix yet
Fix from $1,950 2026-01-30
Hg10 Firmware HIGH 7.3
CVE-2026-1687

A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the file /boaform/formSamba of t…

No fix yet
Fix from $1,950 2026-01-30
Ac21 Firmware HIGH 8.8
CVE-2026-1638

A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mD…

Mitigation only
Fix from $1,950 2026-01-30
Ac21 Firmware HIGH 8.8
CVE-2026-1637

A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWa…

Mitigation only
Fix from $1,950 2026-01-29
Ax12 Pro Firmware HIGH 8.1
CVE-2026-1610

A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. …

Mitigation only
Fix from $1,950 2026-01-29
W30e Firmware CRITICAL 9.8
CVE-2026-24436

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authenti…

Fix: after 16.01.0.19
Fix from $2,300 2026-01-26
W30e Firmware HIGH 8.8
CVE-2026-24440

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interfac…

Fix: after 16.01.0.19
Fix from $1,950 2026-01-26
W30e Firmware MEDIUM 6.5
CVE-2026-24435

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on a…

Fix: after 16.01.0.19
Fix from $1,600 2026-01-26
W30e Firmware MEDIUM 6.5
CVE-2026-24439

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on…

Fix: after 16.01.0.19
Fix from $1,600 2026-01-26
W30e Firmware MEDIUM 5.5
CVE-2026-24437

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-contr…

Fix: after 16.01.0.19
Fix from $1,600 2026-01-26
W30e Firmware CRITICAL 9.8
CVE-2026-24429

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication …

Fix: after 16.01.0.19
Fix from $2,300 2026-01-26
W30e Firmware HIGH 8.8
CVE-2026-24428

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a…

Fix: after 16.01.0.19
Fix from $1,950 2026-01-26
W30e Firmware HIGH 7.5
CVE-2026-24430

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive account credentials in cleartext within HTTP respon…

Fix: after 16.01.0.19
Fix from $1,950 2026-01-26
W30e Firmware MEDIUM 6.5
CVE-2026-24431

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administ…

Fix: after 16.01.0.19
Fix from $1,600 2026-01-26
W30e Firmware MEDIUM 5.4
CVE-2026-24433

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vulnerability in the user creati…

Fix: after 16.01.0.19
Fix from $1,600 2026-01-26