Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-4299
A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the function setSchedWifi of the file …
Ac1206 Firmware
after 15.03.06.23
CRITICAL 9.8
CVE-2025-4298
A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affects the function formSetCfm of …
Ac1206 Firmware
after 15.03.06.23
CRITICAL 9.8
CVE-2025-45042
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
Ac9 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-44872
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. Th…
Ac9 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-44877
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This …
Ac9 Firmware
No fix yet
HIGH 8.2
CVE-2025-46633
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic b…
Rx2 Pro Firmware
No fix yet
HIGH 8.2
CVE-2025-46634
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker t…
Rx2 Pro Firmware
No fix yet
HIGH 7.1
CVE-2025-46635
An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.5
CVE-2025-46631EPSS 7%
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet acc…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.5
CVE-2025-46632
Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or …
Rx2 Pro Firmware
No fix yet
HIGH 8.8
CVE-2025-46625
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is auth…
Rx2 Pro Firmware
Mitigation only
HIGH 8.2
CVE-2025-46627
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the …
Rx2 Pro Firmware
No fix yet
HIGH 7.3
CVE-2025-46626
Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an …
Rx2 Pro Firmware
No fix yet
HIGH 7.3
CVE-2025-46628
Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.5
CVE-2025-46629
Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthor…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.5
CVE-2025-46630
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a r…
Rx2 Pro Firmware
No fix yet
MEDIUM 6.3
CVE-2025-44865
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerabi…
W20e Firmware
No fix yet
MEDIUM 6.3
CVE-2025-44866
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerabil…
W20e Firmware
No fix yet
MEDIUM 6.3
CVE-2025-44867
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vu…
W20e Firmware
No fix yet
MEDIUM 6.3
CVE-2025-44864
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerabi…
W20e Firmware
No fix yet
HIGH 8.8
CVE-2025-4007
A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vulnerability is the function cgi…
W12 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-45429
In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to rem…
Ac9 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-45427
In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead…
Ac9 Firmware
No fix yet
CRITICAL 9.8
CVE-2025-45428
In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which…
Ac9 Firmware
No fix yet
HIGH 8.8
CVE-2025-3820EPSS 11%
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysU…
W12 Firmware
No fix yet
HIGH 8.8
CVE-2025-3803
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysSche…
W12 Firmware
No fix yet
HIGH 8.8
CVE-2025-3802
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function…
W12 Firmware
No fix yet
HIGH 8.8
CVE-2025-3786
A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the fi…
Ac15 Firmware
No fix yet
HIGH 7.5
CVE-2025-25454
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
Ac10 Firmware
No fix yet
HIGH 7.5
CVE-2025-25455
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
Ac10 Firmware
No fix yet