VendorsTendaac15_firmwareall versions
Vulnerabilities

Tenda ac15 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

85CVEs
CVE-2020-10987
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
Published 2020-07-13 · Analyzed
10.0KEVEPSS 0.798
CVE-2020-15916
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
Published 2020-07-23 · Modified
10.0EPSS 0.034
CVE-2020-10988
A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.
Published 2020-07-13 · Modified
10.0EPSS 0.029
CVE-2022-28557
There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution
Published 2022-05-04 · Modified
9.8EPSS 0.226
CVE-2022-40851
Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.
Published 2022-09-23 · Modified
9.8EPSS 0.097
CVE-2024-2851
Tenda AC15 setsambacfg formSetSambaConf os command injection
Published 2024-03-24 · Modified
9.8EPSS 0.040
CVE-2018-18728
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.
Published 2018-10-28 · Modified
9.8EPSS 0.030
CVE-2021-44971
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
Published 2022-01-28 · Modified
9.8EPSS 0.021
CVE-2024-2809
Tenda AC15 SetFirewallCfg formSetFirewallCfg stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.019
CVE-2026-24105
An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.
Published 2026-03-02 · Analyzed
9.8EPSS 0.017
CVE-2025-25632
Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.
Published 2025-03-05 · Analyzed
9.8EPSS 0.017
CVE-2026-24101
An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.
Published 2026-03-02 · Analyzed
9.8EPSS 0.017
CVE-2024-2811
Tenda AC15 WifiWpsStart formWifiWpsStart stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.015
CVE-2023-36103
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
Published 2024-09-10 · Analyzed
9.8EPSS 0.014
CVE-2024-2808
Tenda AC15 QuickIndex formQuickIndex stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.014
CVE-2024-2807
Tenda AC15 expandDlnaFile formExpandDlnaFile stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.014
CVE-2018-18729
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy to a variable placed on the heap, which can leak sensitive information or even hijack program control flow.
Published 2018-10-28 · Modified
9.8EPSS 0.013
CVE-2024-2813
Tenda AC15 fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.013
CVE-2024-2806
Tenda AC15 addWifiMacFilter stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.013
CVE-2024-2815
Tenda AC15 Cookie execCommand R7WebsSecurityHandler stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.013
CVE-2024-2814
Tenda AC15 DhcpListClient fromDhcpListClient stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.013
CVE-2024-2810
Tenda AC15 WifiWpsOOB formWifiWpsOOB stack-based overflow
Published 2024-03-22 · Modified
9.8EPSS 0.013
CVE-2024-2850
Tenda AC15 saveParentControlInfo stack-based overflow
Published 2024-03-24 · Modified
9.8EPSS 0.013
CVE-2024-2852
Tenda AC15 saveParentControlInfo stack-based overflow
Published 2024-03-24 · Modified
9.8EPSS 0.013
CVE-2024-2855
Tenda AC15 SetSysTimeCfg fromSetSysTime stack-based overflow
Published 2024-03-24 · Modified
9.8EPSS 0.013
CVE-2026-3400
Tenda AC15 TextEditingConversion stack-based overflow
Published 2026-03-01 · Analyzed
9.8EPSS 0.011
CVE-2022-37175
Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.
Published 2022-08-19 · Modified
9.8EPSS 0.010
CVE-2023-30372
In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30370
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30373
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-39673
Tenda AC15 V1.0BR_V15.03.05.18_multi_TD01 was discovered to contain a buffer overflow via the function FUN_00010e34().
Published 2023-08-18 · Modified
9.8EPSS 0.008
CVE-2023-30369
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30375
In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30371
In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30378
In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30376
In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2025-29462
A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.
Published 2025-04-03 · Analyzed
9.8EPSS 0.006
CVE-2025-63666
Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie and replay it to access protected resources.
Published 2025-11-12 · Analyzed
9.8EPSS 0.005
CVE-2026-24103
A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.
Published 2026-03-03 · Analyzed
9.8EPSS 0.004
CVE-2025-0566
Tenda AC15 SetDevNetName formSetDevNetName stack-based overflow
Published 2025-01-19 · Analyzed
9.0EPSS 0.087
1 / 3Next →