VendorsTendaac51.0
Vulnerabilities

Tenda AC5 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2021-44971
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
Published 2022-01-28 · Modified
9.8EPSS 0.021
CVE-2023-41556
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetIpMacBind.
Published 2023-08-30 · Modified
9.8EPSS 0.011
CVE-2025-5863
Tenda AC5 SetRebootTimer formSetRebootTimer stack-based overflow
Published 2025-06-09 · Analyzed
9.8EPSS 0.010
CVE-2023-25220
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.010
CVE-2023-25218
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.010
CVE-2023-25210
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetSysTime function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.009
CVE-2023-25219
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.009
CVE-2023-25217
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formWifiBasicSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.009
CVE-2023-25216
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.009
CVE-2023-25215
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.009
CVE-2023-25214
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.009
CVE-2023-25213
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the check_param_changed function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.009
CVE-2023-25212
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetWirelessRepeat function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.009
CVE-2023-25211
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
Published 2023-04-07 · Modified
9.8EPSS 0.009
CVE-2023-38935
Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.
Published 2023-08-07 · Modified
9.8EPSS 0.009
CVE-2023-38936
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
Published 2023-08-07 · Modified
9.8EPSS 0.009
CVE-2023-41563
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-41562
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-41561
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-38937
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-41559
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-41557
Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-41553
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetStaticRouteCfg.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-38933
Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38931
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38930
Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2026-4902
Tenda AC5 POST Request addressNat fromAddressNat memory corruption
Published 2026-03-26 · Analyzed
9.0EPSS 0.010
CVE-2026-4903
Tenda AC5 POST Request QuickIndex formQuickIndex memory corruption
Published 2026-03-26 · Analyzed
9.0EPSS 0.010
CVE-2026-4904
Tenda AC5 POST Request setcfm formSetCfm stack-based overflow
Published 2026-03-26 · Analyzed
9.0EPSS 0.010
CVE-2026-4905
Tenda AC5 POST Request WifiWpsOOB formWifiWpsOOB stack-based overflow
Published 2026-03-26 · Analyzed
9.0EPSS 0.010
CVE-2026-4906
Tenda AC5 POST Request WizardHandle decodePwd stack-based overflow
Published 2026-03-27 · Analyzed
9.0EPSS 0.010
CVE-2025-5794
Tenda AC5 setPptpUserList formSetPPTPUserList buffer overflow
Published 2025-06-06 · Analyzed
9.0EPSS 0.010
CVE-2025-5795
Tenda AC5 AdvSetLanip fromadvsetlanip buffer overflow
Published 2025-06-06 · Analyzed
9.0EPSS 0.010
CVE-2025-6887
Tenda AC5 SetSysTimeCfg stack-based overflow
Published 2025-06-30 · Analyzed
9.0EPSS 0.009
CVE-2025-6886
Tenda AC5 openSchedWifi stack-based overflow
Published 2025-06-30 · Analyzed
9.0EPSS 0.009