VendorsTendaac15_firmware15.03.05.19
Vulnerabilities

Tenda ac15 Firmware 15.03.05.19

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2020-10987
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
Published 2020-07-13 · Analyzed
10.0KEVEPSS 0.798
CVE-2020-15916
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
Published 2020-07-23 · Modified
10.0EPSS 0.034
CVE-2020-10988
A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.
Published 2020-07-13 · Modified
10.0EPSS 0.029
CVE-2022-40851
Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.
Published 2022-09-23 · Modified
9.8EPSS 0.097
CVE-2025-25632
Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.
Published 2025-03-05 · Analyzed
9.8EPSS 0.017
CVE-2024-2855
Tenda AC15 SetSysTimeCfg fromSetSysTime stack-based overflow
Published 2024-03-24 · Modified
9.8EPSS 0.013
CVE-2023-30373
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30372
In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30370
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30369
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30371
In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30375
In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30376
In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2023-30378
In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.
Published 2023-04-24 · Modified
9.8EPSS 0.008
CVE-2024-10662
Tenda AC15 SetOnlineDevName formSetDeviceName stack-based overflow
Published 2024-11-01 · Analyzed
9.0EPSS 0.013
CVE-2024-10661
Tenda AC15 SetDlnaCfg stack-based overflow
Published 2024-11-01 · Analyzed
9.0EPSS 0.012
CVE-2025-3786
Tenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflow
Published 2025-04-18 · Analyzed
9.0EPSS 0.011
CVE-2024-32303
Tenda AC15 v15.03.20_multi, v15.03.05.19, and v15.03.05.18 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
Published 2024-04-17 · Analyzed
8.0EPSS 0.004
CVE-2022-44156
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.
Published 2022-11-21 · Modified
7.5EPSS 0.009
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2022-43259
Tenda AC15 V15.03.05.18 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function.
Published 2022-10-18 · Modified
7.5EPSS 0.008
CVE-2025-55564
Tenda AC15 v15.03.05.19_multi_TD01 has a stack overflow via the list parameter in the fromSetIpMacBind function.
Published 2025-08-21 · Modified
7.5EPSS 0.004
CVE-2020-10986
A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.
Published 2020-07-13 · Modified
7.1EPSS 0.006
CVE-2025-25634
A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based buffer overflow.
Published 2025-03-05 · Analyzed
6.5EPSS 0.003
CVE-2020-10989
An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.
Published 2020-07-13 · Modified
6.1EPSS 0.009