VendorsTendaac10_firmwareall versions
Vulnerabilities

Tenda ac10 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

92CVEs
CVE-2023-38933
Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38937
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2025-5629
Tenda AC10 HTTP SetPptpServerCfg formSetPPTPServer buffer overflow
Published 2025-06-05 · Analyzed
9.8EPSS 0.008
CVE-2025-12622
Tenda AC10 SysRunCmd formSysRunCmd buffer overflow
Published 2025-11-03 · Analyzed
9.8EPSS 0.008
CVE-2025-67073
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.
Published 2025-12-17 · Analyzed
9.8EPSS 0.007
CVE-2025-25456
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
Published 2025-04-15 · Analyzed
9.8EPSS 0.006
CVE-2025-25674
Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.
Published 2025-02-20 · Analyzed
9.8EPSS 0.005
CVE-2024-2581
Tenda AC10 SetStaticRouteCfg fromSetRouteStatic stack-based overflow
Published 2024-03-18 · Analyzed
9.0EPSS 0.013
CVE-2024-11248
Tenda AC10 SetSysAutoRebbotCfg formSetRebootTimer stack-based overflow
Published 2024-11-15 · Analyzed
9.0EPSS 0.013
CVE-2024-11061
Tenda AC10 fast_setting_wifi_set FUN_0044db3c stack-based overflow
Published 2024-11-11 · Analyzed
9.0EPSS 0.012
CVE-2024-11056
Tenda AC10 WifiExtraSet FUN_0046AC38 stack-based overflow
Published 2024-11-10 · Analyzed
9.0EPSS 0.011
CVE-2026-5550
Tenda AC10 httpd fromSysToolChangePwd stack-based overflow
Published 2026-04-05 · Analyzed
9.0EPSS 0.010
CVE-2025-3161
Tenda AC10 ShutdownSetAdd stack-based overflow
Published 2025-04-03 · Analyzed
9.0EPSS 0.009
CVE-2026-5548
Tenda AC10 httpd fromSysToolChangePwd stack-based overflow
Published 2026-04-05 · Analyzed
9.0EPSS 0.008
CVE-2025-4896
Tenda AC10 UserCongratulationsExec buffer overflow
Published 2025-05-18 · Analyzed
9.0EPSS 0.008
CVE-2025-8178
Tenda AC10 RequestsProcessLaid heap-based overflow
Published 2025-07-26 · Analyzed
9.0EPSS 0.008
CVE-2026-5547
Tenda AC10 httpd formAddMacfilterRule os command injection
Published 2026-04-05 · Analyzed
8.8EPSS 0.041
CVE-2025-0528
Tenda AC8/AC10/AC18 HTTP Request telnet command injection
Published 2025-01-17 · Analyzed
8.6EPSS 0.059
CVE-2018-14557
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, a causing buffer overflow.
Published 2019-04-25 · Modified
7.8EPSS 0.014
CVE-2018-14559
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.
Published 2019-04-25 · Modified
7.8EPSS 0.014
CVE-2018-18708
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.014
CVE-2018-18706
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18707
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18709
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18727
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18730
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18731
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18732
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2024-33365
Buffer Overflow vulnerability in Tenda AC10 v4 US_AC10V4.0si_V16.03.10.20_cn allows a remote attacker to execute arbitrary code via the Virtual_Data_Check function in the bin/httpd component.
Published 2024-07-29 · Analyzed
7.5EPSS 0.010
CVE-2022-46109
Tenda AC15 V15.03.06.23 is vulnerable to Buffer Overflow via function formSetClientState.
Published 2022-12-16 · Modified
7.5EPSS 0.009
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2026-5549
Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key
Published 2026-04-05 · Analyzed
7.5EPSS 0.007
CVE-2025-25457
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.
Published 2025-04-17 · Analyzed
7.5EPSS 0.007
CVE-2025-25454
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
Published 2025-04-17 · Analyzed
7.5EPSS 0.006
CVE-2025-25455
Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
Published 2025-04-17 · Analyzed
7.5EPSS 0.006
CVE-2024-32317
Tenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.
Published 2024-04-17 · Analyzed
7.5EPSS 0.004
CVE-2025-57215
Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to contain a stack overflow via the function get_parentControl_list_Info.
Published 2025-08-28 · Analyzed
7.5EPSS 0.004
CVE-2025-9309
Tenda AC10 MD5 Hash shadow hard-coded credentials
Published 2025-08-21 · Analyzed
7.0EPSS 0.002
CVE-2023-34568
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.
Published 2023-06-08 · Modified
6.7EPSS 0.003
CVE-2023-34567
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.
Published 2023-06-08 · Modified
6.7EPSS 0.003
← Prev2 / 3Next →