VendorsTendaac18_firmware15.03.05.05
Vulnerabilities

Tenda ac18 Firmware 15.03.05.05

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

38CVEs
CVE-2024-2854
Tenda AC18 setsambacfg formSetSambaConf os command injection
Published 2024-03-24 · Modified
9.8EPSS 0.039
CVE-2022-35201
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
Published 2022-08-19 · Modified
9.8EPSS 0.035
CVE-2025-5606
Tenda AC18 SetIPTVCfg formSetIptv command injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.034
CVE-2024-28545
Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.
Published 2024-03-26 · Analyzed
9.8EPSS 0.023
CVE-2026-31255
A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.
Published 2026-04-27 · Modified
9.8EPSS 0.015
CVE-2022-38309
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38314
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38310
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38313
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38311
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2022-38312
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
Published 2022-09-07 · Modified
9.8EPSS 0.011
CVE-2024-33835
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.
Published 2024-05-01 · Analyzed
9.8EPSS 0.008
CVE-2024-28537
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
Published 2024-03-18 · Analyzed
9.8EPSS 0.008
CVE-2024-28553
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.
Published 2024-03-12 · Modified
9.8EPSS 0.008
CVE-2024-28535
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.
Published 2024-03-12 · Modified
9.8EPSS 0.008
CVE-2022-44174
Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.
Published 2022-11-21 · Modified
9.8EPSS 0.007
CVE-2024-2485
Tenda AC18 SetSpeedWan formSetSpeedWan stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.017
CVE-2024-2487
Tenda AC18 SetOnlineDevName formSetDeviceName stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.016
CVE-2024-2489
Tenda AC18 SetNetControlList formSetQosBand stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.016
CVE-2024-2490
Tenda AC18 openSchedWifi setSchedWifi stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.016
CVE-2024-2486
Tenda AC18 QuickIndex formQuickIndex stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.016
CVE-2024-2488
Tenda AC18 SetPptpServerCfg formSetPPTPServer stack-based overflow
Published 2024-03-15 · Analyzed
9.0EPSS 0.015
CVE-2024-2558
Tenda AC18 execCommand formexeCommand stack-based overflow
Published 2024-03-17 · Analyzed
9.0EPSS 0.013
CVE-2024-2547
Tenda AC18 R7WebsSecurityHandler stack-based overflow
Published 2024-03-17 · Analyzed
9.0EPSS 0.012
CVE-2025-5609
Tenda AC18 AdvSetLanip fromadvsetlanip buffer overflow
Published 2025-06-04 · Analyzed
9.0EPSS 0.010
CVE-2025-5608
Tenda AC18 SetSysAutoRebbotCfg formsetreboottimer buffer overflow
Published 2025-06-04 · Analyzed
9.0EPSS 0.010
CVE-2025-5607
Tenda AC18 setPptpUserList formSetPPTPUserList buffer overflow
Published 2025-06-04 · Analyzed
9.0EPSS 0.010
CVE-2025-14993
Tenda AC18 HTTP Request SetDlnaCfg sprintf stack-based overflow
Published 2025-12-21 · Analyzed
9.0EPSS 0.008
CVE-2025-14992
Tenda AC18 HTTP Request GetParentControlInfo strcpy stack-based overflow
Published 2025-12-21 · Analyzed
9.0EPSS 0.007
CVE-2024-30891
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.
Published 2024-04-05 · Analyzed
8.8EPSS 0.019
CVE-2025-63835
A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.
Published 2025-11-10 · Modified
8.8EPSS 0.006
CVE-2024-28551
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the ssid parameter of form_fast_setting_wifi_set function.
Published 2024-03-26 · Analyzed
7.5EPSS 0.008
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2024-28547
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.
Published 2024-03-18 · Analyzed
6.5EPSS 0.005
CVE-2024-2559
Tenda AC18 SysToolReboot fromSysToolReboot cross-site request forgery
Published 2024-03-17 · Analyzed
6.5EPSS 0.003
CVE-2025-63834
A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.
Published 2025-11-10 · Modified
5.4EPSS 0.002
CVE-2024-2560
Tenda AC18 SysToolRestoreSet fromSysToolRestoreSet cross-site request forgery
Published 2024-03-17 · Analyzed
5.0EPSS 0.004
CVE-2024-28550
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.
Published 2024-03-18 · Analyzed
4.3EPSS 0.004