VendorsTendaac15all versions
Vulnerabilities

Tenda AC15

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

85CVEs
CVE-2025-5850
Tenda AC15 HTTP POST Request SetLEDCf formsetschedled buffer overflow
Published 2025-06-08 · Analyzed
9.0EPSS 0.062
CVE-2025-10443
Tenda AC9/AC15 exeCommand formexeCommand buffer overflow
Published 2025-09-15 · Analyzed
9.0EPSS 0.040
CVE-2024-2805
Tenda AC15 SetSpeedWan formSetSpeedWan stack-based overflow
Published 2024-03-22 · Analyzed
9.0EPSS 0.016
CVE-2024-10662
Tenda AC15 SetOnlineDevName formSetDeviceName stack-based overflow
Published 2024-11-01 · Analyzed
9.0EPSS 0.013
CVE-2024-10661
Tenda AC15 SetDlnaCfg stack-based overflow
Published 2024-11-01 · Analyzed
9.0EPSS 0.012
CVE-2025-3786
Tenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflow
Published 2025-04-18 · Analyzed
9.0EPSS 0.011
CVE-2026-4975
Tenda AC15 POST Request setcfm formSetCfm memory corruption
Published 2026-03-27 · Analyzed
9.0EPSS 0.010
CVE-2026-5830
Tenda AC15 SysToolChangePwd websGetVar stack-based overflow
Published 2026-04-09 · Analyzed
9.0EPSS 0.010
CVE-2025-5848
Tenda AC15 HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflow
Published 2025-06-08 · Analyzed
9.0EPSS 0.010
CVE-2025-5849
Tenda AC15 HTTP POST Request SetRemoteWebCfg formSetSafeWanWebMan stack-based overflow
Published 2025-06-08 · Analyzed
9.0EPSS 0.010
CVE-2025-5851
Tenda AC15 HTTP POST Request AdvSetLanip fromadvsetlanip buffer overflow
Published 2025-06-08 · Analyzed
9.0EPSS 0.010
CVE-2025-11386
Tenda AC15 POST Parameter SetDDNSCfg stack-based overflow
Published 2025-10-07 · Analyzed
9.0EPSS 0.008
CVE-2025-11387
Tenda AC15 fast_setting_pppoe_set stack-based overflow
Published 2025-10-07 · Analyzed
9.0EPSS 0.008
CVE-2025-11388
Tenda AC15 setNotUpgrade stack-based overflow
Published 2025-10-07 · Analyzed
9.0EPSS 0.008
CVE-2025-11389
Tenda AC15 saveAutoQos stack-based overflow
Published 2025-10-07 · Modified
9.0EPSS 0.008
CVE-2025-10442
Tenda AC9/AC15 exeCommand formexeCommand os command injection
Published 2025-09-15 · Analyzed
8.8EPSS 0.083
CVE-2024-2812
Tenda AC15 WriteFacMac formWriteFacMac os command injection
Published 2024-03-22 · Modified
8.8EPSS 0.041
CVE-2017-16923
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to execute arbitrary OS commands via a crafted cgi-bin/luci/usbeject?dev_name= GET request from the LAN. This occurs because the "sub_A6E8 usbeject_process_entry" function executes a system function with untrusted input.
Published 2017-11-21 · Modified
8.8EPSS 0.026
CVE-2024-30645
Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.
Published 2024-03-29 · Analyzed
8.0EPSS 0.010
CVE-2024-32303
Tenda AC15 v15.03.20_multi, v15.03.05.19, and v15.03.05.18 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
Published 2024-04-17 · Analyzed
8.0EPSS 0.004
CVE-2018-18708
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.014
CVE-2018-18707
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18730
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18731
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18732
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18709
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18727
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18706
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2022-28556
Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in stack overflow. Similarly, this vulnerability can be used together with CVE-2021-44971
Published 2022-05-04 · Modified
7.5EPSS 0.011
CVE-2022-44156
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.
Published 2022-11-21 · Modified
7.5EPSS 0.009
CVE-2022-44167
Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.
Published 2022-11-21 · Modified
7.5EPSS 0.009
CVE-2022-44168
Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function fromSetRouteStatic..
Published 2022-11-21 · Modified
7.5EPSS 0.009
CVE-2022-44169
Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function formSetVirtualSer.
Published 2022-11-21 · Modified
7.5EPSS 0.009
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2022-43259
Tenda AC15 V15.03.05.18 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function.
Published 2022-10-18 · Modified
7.5EPSS 0.008
CVE-2025-55564
Tenda AC15 v15.03.05.19_multi_TD01 has a stack overflow via the list parameter in the fromSetIpMacBind function.
Published 2025-08-21 · Modified
7.5EPSS 0.004
CVE-2020-10986
A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.
Published 2020-07-13 · Modified
7.1EPSS 0.006
CVE-2025-8979
Tenda AC15 Firmware Update check_fw data authenticity
Published 2025-08-14 · Analyzed
6.8EPSS 0.004
CVE-2017-16936
Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to read arbitrary files via a cgi-bin/luci/request?op=1&path= URI that uses directory traversal sequences after a /usb/ substring.
Published 2017-11-24 · Modified
6.5EPSS 0.010
CVE-2024-2816
Tenda AC15 SysToolReboot fromSysToolReboot cross-site request forgery
Published 2024-03-22 · Modified
6.5EPSS 0.004
← Prev2 / 3Next →