VendorsTendaac18any version
Vulnerabilities

Tenda AC18 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

100CVEs
CVE-2022-44171
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.
Published 2022-11-21 · Modified
9.8EPSS 0.007
CVE-2022-44172
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.
Published 2022-11-21 · Modified
9.8EPSS 0.007
CVE-2022-44174
Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.
Published 2022-11-21 · Modified
9.8EPSS 0.007
CVE-2024-57579
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientState function.
Published 2025-01-16 · Modified
9.8EPSS 0.007
CVE-2024-2485
Tenda AC18 SetSpeedWan formSetSpeedWan stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.017
CVE-2024-2487
Tenda AC18 SetOnlineDevName formSetDeviceName stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.016
CVE-2024-2489
Tenda AC18 SetNetControlList formSetQosBand stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.016
CVE-2024-2490
Tenda AC18 openSchedWifi setSchedWifi stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.016
CVE-2024-2486
Tenda AC18 QuickIndex formQuickIndex stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.016
CVE-2024-2488
Tenda AC18 SetPptpServerCfg formSetPPTPServer stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.015
CVE-2024-2558
Tenda AC18 execCommand formexeCommand stack-based overflow
Published 2024-03-17 · Analyzed
9.0EPSS 0.013
CVE-2025-11327
Tenda AC18 SetUpnpCfg stack-based overflow
Published 2025-10-06 · Analyzed
9.0EPSS 0.012
CVE-2025-11326
Tenda AC18 WifiMacFilterSet stack-based overflow
Published 2025-10-06 · Modified
9.0EPSS 0.012
CVE-2024-2547
Tenda AC18 R7WebsSecurityHandler stack-based overflow
Published 2024-03-17 · Analyzed
9.0EPSS 0.012
CVE-2025-11328
Tenda AC18 SetDDNSCfg stack-based overflow
Published 2025-10-06 · Analyzed
9.0EPSS 0.011
CVE-2024-2546
Tenda AC18 fromSetWirelessRepeat stack-based overflow
Published 2024-03-17 · Analyzed
9.0EPSS 0.010
CVE-2025-5607
Tenda AC18 setPptpUserList formSetPPTPUserList buffer overflow
Published 2025-06-04 · Analyzed
9.0EPSS 0.010
CVE-2025-5608
Tenda AC18 SetSysAutoRebbotCfg formsetreboottimer buffer overflow
Published 2025-06-04 · Analyzed
9.0EPSS 0.010
CVE-2025-5609
Tenda AC18 AdvSetLanip fromadvsetlanip buffer overflow
Published 2025-06-04 · Analyzed
9.0EPSS 0.010
CVE-2025-11324
Tenda AC18 setNotUpgrade stack-based overflow
Published 2025-10-06 · Analyzed
9.0EPSS 0.008
CVE-2025-9023
Tenda AC7/AC18 SetLEDCfg formSetSchedLed buffer overflow
Published 2025-08-15 · Analyzed
9.0EPSS 0.008
CVE-2025-11123
Tenda AC18 saveAutoQos stack-based overflow
Published 2025-09-28 · Analyzed
9.0EPSS 0.008
CVE-2025-11122
Tenda AC18 WizardHandle stack-based overflow
Published 2025-09-28 · Analyzed
9.0EPSS 0.008
CVE-2025-11325
Tenda AC18 fast_setting_pppoe_set stack-based overflow
Published 2025-10-06 · Modified
9.0EPSS 0.008
CVE-2025-14993
Tenda AC18 HTTP Request SetDlnaCfg sprintf stack-based overflow
Published 2025-12-21 · Analyzed
9.0EPSS 0.008
CVE-2025-14992
Tenda AC18 HTTP Request GetParentControlInfo strcpy stack-based overflow
Published 2025-12-21 · Analyzed
9.0EPSS 0.007
CVE-2025-11121
Tenda AC18 AdvSetLanip command injection
Published 2025-09-28 · Analyzed
8.8EPSS 0.037
CVE-2017-16923
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to execute arbitrary OS commands via a crafted cgi-bin/luci/usbeject?dev_name= GET request from the LAN. This occurs because the "sub_A6E8 usbeject_process_entry" function executes a system function with untrusted input.
Published 2017-11-21 · Modified
8.8EPSS 0.026
CVE-2024-30891
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.
Published 2024-04-05 · Analyzed
8.8EPSS 0.019
CVE-2025-63835
A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.
Published 2025-11-10 · Modified
8.8EPSS 0.006
CVE-2024-33181
Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parameter at ip/goform/addWifiMacFilter.
Published 2024-07-16 · Analyzed
8.8EPSS 0.006
CVE-2024-57578
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm function.
Published 2025-01-16 · Analyzed
8.8EPSS 0.005
CVE-2025-0528
Tenda AC8/AC10/AC18 HTTP Request telnet command injection
Published 2025-01-17 · Analyzed
8.6EPSS 0.059
CVE-2024-34974
Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.
Published 2024-05-10 · Analyzed
8.2EPSS 0.007
CVE-2018-18708
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.014
CVE-2018-18707
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18730
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18731
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18709
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18706
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
← Prev2 / 3Next →