VendorsTendaac18all versions
Vulnerabilities

Tenda AC18

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

101CVEs
CVE-2024-2854
Tenda AC18 setsambacfg formSetSambaConf os command injection
Published 2024-03-24 · Modified
9.8EPSS 0.039
CVE-2022-35201
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
Published 2022-08-19 · Modified
9.8EPSS 0.035
CVE-2025-5606
Tenda AC18 SetIPTVCfg formSetIptv command injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.034
CVE-2018-18728
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.
Published 2018-10-28 · Modified
9.8EPSS 0.030
CVE-2023-30135
Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the setUsbUnload function.
Published 2023-05-05 · Modified
9.8EPSS 0.024
CVE-2024-28545
Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.
Published 2024-03-26 · Analyzed
9.8EPSS 0.023
CVE-2024-57583
Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.
Published 2025-01-16 · Modified
9.8EPSS 0.015
CVE-2026-31255
A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.
Published 2026-04-27 · Modified
9.8EPSS 0.015
CVE-2022-30477
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetClientState request.
Published 2022-05-26 · Modified
9.8EPSS 0.014
CVE-2022-30476
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetFirewallCfg request.
Published 2022-05-26 · Modified
9.8EPSS 0.014
CVE-2022-30472
Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat
Published 2022-05-26 · Modified
9.8EPSS 0.014
CVE-2022-30474
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request.
Published 2022-05-26 · Modified
9.8EPSS 0.014
CVE-2018-18729
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy to a variable placed on the heap, which can leak sensitive information or even hijack program control flow.
Published 2018-10-28 · Modified
9.8EPSS 0.013
CVE-2023-38823
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
Published 2023-11-20 · Modified
9.8EPSS 0.012
CVE-2022-40854
Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set
Published 2022-09-23 · Modified
9.8EPSS 0.011
CVE-2022-38310
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38311
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38312
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38313
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38314
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38309
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2023-24166
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.
Published 2023-01-26 · Modified
9.8EPSS 0.011
CVE-2022-44183
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.
Published 2022-11-21 · Modified
9.8EPSS 0.011
CVE-2023-24167
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node.
Published 2023-01-26 · Modified
9.8EPSS 0.010
CVE-2023-24164
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318.
Published 2023-01-26 · Modified
9.8EPSS 0.010
CVE-2023-24165
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo.
Published 2023-01-26 · Modified
9.8EPSS 0.010
CVE-2023-24170
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.
Published 2023-01-26 · Modified
9.8EPSS 0.010
CVE-2023-24169
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.
Published 2023-01-26 · Modified
9.8EPSS 0.010
CVE-2022-43260
Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.
Published 2022-10-18 · Modified
9.8EPSS 0.009
CVE-2024-33835
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.
Published 2024-05-01 · Analyzed
9.8EPSS 0.008
CVE-2022-44175
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
Published 2022-11-21 · Modified
9.8EPSS 0.008
CVE-2022-44176
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.
Published 2022-11-21 · Modified
9.8EPSS 0.008
CVE-2024-57575
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
Published 2025-01-16 · Modified
9.8EPSS 0.008
CVE-2024-28537
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
Published 2024-03-18 · Analyzed
9.8EPSS 0.008
CVE-2024-57580
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
Published 2025-01-16 · Modified
9.8EPSS 0.008
CVE-2024-57582
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.
Published 2025-01-16 · Modified
9.8EPSS 0.008
CVE-2024-57581
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
Published 2025-01-16 · Modified
9.8EPSS 0.008
CVE-2022-44177
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.
Published 2022-11-21 · Modified
9.8EPSS 0.007
CVE-2022-44178
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.
Published 2022-11-21 · Modified
9.8EPSS 0.007
CVE-2022-44180
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.
Published 2022-11-21 · Modified
9.8EPSS 0.007
1 / 3Next →