VendorsTendaac18any version
Vulnerabilities

Tenda AC18 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

100CVEs
CVE-2018-18731
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18730
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2024-41630
Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.
Published 2024-07-31 · Analyzed
7.6EPSS 0.010
CVE-2022-30475
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/WifiExtraSet request.
Published 2022-05-26 · Modified
7.5EPSS 0.012
CVE-2022-30473
Tenda AC Series Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function form_fast_setting_wifi_set
Published 2022-05-26 · Modified
7.5EPSS 0.012
CVE-2024-28551
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the ssid parameter of form_fast_setting_wifi_set function.
Published 2024-03-26 · Analyzed
7.5EPSS 0.008
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2025-60660
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.
Published 2025-10-02 · Analyzed
7.5EPSS 0.005
CVE-2025-60662
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.
Published 2025-10-02 · Analyzed
7.5EPSS 0.005
CVE-2025-60663
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.
Published 2025-10-02 · Analyzed
7.5EPSS 0.004
CVE-2025-8182
Tenda AC18 Samba smb.conf weak password
Published 2025-07-26 · Analyzed
7.4EPSS 0.004
CVE-2022-40861
Tenda AC18 router V15.03.05.19 contains a stack overflow vulnerability in the formSetQosBand->FUN_0007db78 function with the request /goform/SetNetControlList/
Published 2022-09-23 · Modified
7.2EPSS 0.011
CVE-2017-16936
Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to read arbitrary files via a cgi-bin/luci/request?op=1&path= URI that uses directory traversal sequences after a /usb/ substring.
Published 2017-11-24 · Modified
6.5EPSS 0.010
CVE-2024-28547
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.
Published 2024-03-18 · Analyzed
6.5EPSS 0.005
CVE-2024-2559
Tenda AC18 SysToolReboot fromSysToolReboot cross-site request forgery
Published 2024-03-17 · Analyzed
6.5EPSS 0.003
CVE-2024-57577
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
Published 2025-01-16 · Analyzed
5.7EPSS 0.003
CVE-2025-63834
A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.
Published 2025-11-10 · Modified
5.4EPSS 0.002
CVE-2025-60661
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.
Published 2025-10-02 · Analyzed
5.3EPSS 0.004
CVE-2024-2560
Tenda AC18 SysToolRestoreSet fromSysToolRestoreSet cross-site request forgery
Published 2024-03-17 · Analyzed
5.0EPSS 0.004
CVE-2024-28550
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.
Published 2024-03-18 · Analyzed
4.3EPSS 0.004
← Prev3 / 3