VendorsTendaac104.0
Vulnerabilities

Tenda AC10 4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

54CVEs
CVE-2023-42320
Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.
Published 2023-09-18 · Modified
9.8EPSS 0.012
CVE-2024-2856
Tenda AC10 SetSysTimeCfg fromSetSysTime stack-based overflow
Published 2024-03-24 · Modified
9.8EPSS 0.012
CVE-2023-27015
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75C0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-27016
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-27012
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-27014
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC38 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-27019
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-27017
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-27020
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-27018
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-27013
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-27021
Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.011
CVE-2023-45480
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the function sub_47D878.
Published 2023-11-29 · Modified
9.8EPSS 0.010
CVE-2023-45482
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.
Published 2023-11-29 · Modified
9.8EPSS 0.010
CVE-2023-45481
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg.
Published 2023-11-29 · Modified
9.8EPSS 0.010
CVE-2023-45483
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcontrol_time.
Published 2023-11-29 · Modified
9.8EPSS 0.010
CVE-2023-45479
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in the function sub_49E098.
Published 2023-11-29 · Modified
9.8EPSS 0.010
CVE-2023-45484
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGuestBasic.
Published 2023-11-29 · Modified
9.8EPSS 0.010
CVE-2023-34566
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.
Published 2023-06-08 · Modified
9.8EPSS 0.009
CVE-2023-38935
Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.
Published 2023-08-07 · Modified
9.8EPSS 0.009
CVE-2023-38931
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38937
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2025-12622
Tenda AC10 SysRunCmd formSysRunCmd buffer overflow
Published 2025-11-03 · Analyzed
9.8EPSS 0.008
CVE-2025-67073
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.
Published 2025-12-17 · Analyzed
9.8EPSS 0.007
CVE-2025-25456
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
Published 2025-04-15 · Analyzed
9.8EPSS 0.006
CVE-2024-11248
Tenda AC10 SetSysAutoRebbotCfg formSetRebootTimer stack-based overflow
Published 2024-11-15 · Analyzed
9.0EPSS 0.013
CVE-2024-11061
Tenda AC10 fast_setting_wifi_set FUN_0044db3c stack-based overflow
Published 2024-11-11 · Analyzed
9.0EPSS 0.012
CVE-2024-11056
Tenda AC10 WifiExtraSet FUN_0046AC38 stack-based overflow
Published 2024-11-10 · Analyzed
9.0EPSS 0.011
CVE-2026-5550
Tenda AC10 httpd fromSysToolChangePwd stack-based overflow
Published 2026-04-05 · Analyzed
9.0EPSS 0.010
CVE-2026-5548
Tenda AC10 httpd fromSysToolChangePwd stack-based overflow
Published 2026-04-05 · Analyzed
9.0EPSS 0.008
CVE-2026-5547
Tenda AC10 httpd formAddMacfilterRule os command injection
Published 2026-04-05 · Analyzed
8.8EPSS 0.041
CVE-2024-33365
Buffer Overflow vulnerability in Tenda AC10 v4 US_AC10V4.0si_V16.03.10.20_cn allows a remote attacker to execute arbitrary code via the Virtual_Data_Check function in the bin/httpd component.
Published 2024-07-29 · Analyzed
7.5EPSS 0.010
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2026-5549
Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key
Published 2026-04-05 · Analyzed
7.5EPSS 0.007
CVE-2025-25457
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.
Published 2025-04-17 · Analyzed
7.5EPSS 0.007
CVE-2025-25454
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
Published 2025-04-17 · Analyzed
7.5EPSS 0.006
CVE-2025-25455
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
Published 2025-04-17 · Analyzed
7.5EPSS 0.006
CVE-2024-32317
Tenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.
Published 2024-04-17 · Analyzed
7.5EPSS 0.004
CVE-2025-57215
Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to contain a stack overflow via the function get_parentControl_list_Info.
Published 2025-08-28 · Analyzed
7.5EPSS 0.004
CVE-2025-9309
Tenda AC10 MD5 Hash shadow hard-coded credentials
Published 2025-08-21 · Analyzed
7.0EPSS 0.002
1 / 2Next →