VendorsTendaac15any version
Vulnerabilities

Tenda AC15 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

64CVEs
CVE-2020-10987
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
Published 2020-07-13 · Analyzed
10.0KEVEPSS 0.798
CVE-2020-15916
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
Published 2020-07-23 · Modified
10.0EPSS 0.034
CVE-2020-10988
A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.
Published 2020-07-13 · Modified
10.0EPSS 0.029
CVE-2022-40851
Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.
Published 2022-09-23 · Modified
9.8EPSS 0.097
CVE-2024-2851
Tenda AC15 setsambacfg formSetSambaConf os command injection
Published 2024-03-24 · Modified
9.8EPSS 0.040
CVE-2018-18728
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.
Published 2018-10-28 · Modified
9.8EPSS 0.030
CVE-2025-25632
Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.
Published 2025-03-05 · Analyzed
9.8EPSS 0.017
CVE-2024-2811
Tenda AC15 WifiWpsStart formWifiWpsStart stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.015
CVE-2023-36103
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
Published 2024-09-10 · Analyzed
9.8EPSS 0.014
CVE-2018-18729
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy to a variable placed on the heap, which can leak sensitive information or even hijack program control flow.
Published 2018-10-28 · Modified
9.8EPSS 0.013
CVE-2024-2815
Tenda AC15 Cookie execCommand R7WebsSecurityHandler stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.013
CVE-2024-2813
Tenda AC15 fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.013
CVE-2024-2814
Tenda AC15 DhcpListClient fromDhcpListClient stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.013
CVE-2024-2850
Tenda AC15 saveParentControlInfo stack-based overflow
Published 2024-03-24 · Modified
9.8EPSS 0.013
CVE-2026-3400
Tenda AC15 TextEditingConversion stack-based overflow
Published 2026-03-01 · Analyzed
9.8EPSS 0.011
CVE-2022-37175
Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.
Published 2022-08-19 · Modified
9.8EPSS 0.010
CVE-2023-30372
In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30370
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30373
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30378
In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30369
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30371
In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30375
In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30376
In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2025-29462
A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.
Published 2025-04-03 · Analyzed
9.8EPSS 0.006
CVE-2025-63666
Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie and replay it to access protected resources.
Published 2025-11-12 · Analyzed
9.8EPSS 0.005
CVE-2025-0566
Tenda AC15 SetDevNetName formSetDevNetName stack-based overflow
Published 2025-01-19 · Analyzed
9.0EPSS 0.087
CVE-2025-10443
Tenda AC9/AC15 exeCommand formexeCommand buffer overflow
Published 2025-09-15 · Analyzed
9.0EPSS 0.040
CVE-2024-2805
Tenda AC15 SetSpeedWan formSetSpeedWan stack-based overflow
Published 2024-03-22 · Analyzed
9.0EPSS 0.016
CVE-2024-10662
Tenda AC15 SetOnlineDevName formSetDeviceName stack-based overflow
Published 2024-11-01 · Analyzed
9.0EPSS 0.013
CVE-2024-10661
Tenda AC15 SetDlnaCfg stack-based overflow
Published 2024-11-01 · Analyzed
9.0EPSS 0.012
CVE-2025-3786
Tenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflow
Published 2025-04-18 · Analyzed
9.0EPSS 0.011
CVE-2026-5830
Tenda AC15 SysToolChangePwd websGetVar stack-based overflow
Published 2026-04-09 · Analyzed
9.0EPSS 0.010
CVE-2025-11386
Tenda AC15 POST Parameter SetDDNSCfg stack-based overflow
Published 2025-10-07 · Analyzed
9.0EPSS 0.008
CVE-2025-11388
Tenda AC15 setNotUpgrade stack-based overflow
Published 2025-10-07 · Analyzed
9.0EPSS 0.008
CVE-2025-11387
Tenda AC15 fast_setting_pppoe_set stack-based overflow
Published 2025-10-07 · Analyzed
9.0EPSS 0.008
CVE-2025-11389
Tenda AC15 saveAutoQos stack-based overflow
Published 2025-10-07 · Modified
9.0EPSS 0.008
CVE-2025-10442
Tenda AC9/AC15 exeCommand formexeCommand os command injection
Published 2025-09-15 · Analyzed
8.8EPSS 0.083
CVE-2017-16923
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to execute arbitrary OS commands via a crafted cgi-bin/luci/usbeject?dev_name= GET request from the LAN. This occurs because the "sub_A6E8 usbeject_process_entry" function executes a system function with untrusted input.
Published 2017-11-21 · Modified
8.8EPSS 0.026
CVE-2024-32303
Tenda AC15 v15.03.20_multi, v15.03.05.19, and v15.03.05.18 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
Published 2024-04-17 · Analyzed
8.0EPSS 0.004
1 / 2Next →