VendorsTendaac6all versions
Vulnerabilities

Tenda AC6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

112CVEs
CVE-2022-25450
Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.116
CVE-2022-25445
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.
Published 2022-03-18 · Modified
10.0EPSS 0.090
CVE-2022-25447
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25446
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25455
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25453
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25458
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25448
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25456
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25461
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25457
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25460
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25452
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25449
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25451
Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25454
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25459
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2024-10697
Tenda AC6 API Endpoint WriteFacMac formWriteFacMac command injection
Published 2024-11-02 · Modified
9.8EPSS 0.262
CVE-2025-27129
An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.
Published 2025-08-20 · Modified
9.8EPSS 0.021
CVE-2025-0349
Tenda AC6 GetParentControlInfo stack-based overflow
Published 2025-01-09 · Modified
9.8EPSS 0.018
CVE-2024-10698
Tenda AC6 SetOnlineDevName formSetDeviceName stack-based overflow
Published 2024-11-02 · Analyzed
9.8EPSS 0.013
CVE-2023-38823
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
Published 2023-11-20 · Modified
9.8EPSS 0.012
CVE-2023-40838
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_3A1D0' contains a command execution vulnerability.
Published 2023-08-30 · Modified
9.8EPSS 0.011
CVE-2023-40839
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADF3C' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADF3C" function to execute commands.
Published 2023-08-30 · Modified
9.8EPSS 0.010
CVE-2025-5855
Tenda AC6 SetRebootTimer formSetRebootTimer stack-based overflow
Published 2025-06-09 · Analyzed
9.8EPSS 0.010
CVE-2025-1814
Tenda AC6 WifiExtraSet stack-based overflow
Published 2025-03-02 · Analyzed
9.8EPSS 0.010
CVE-2023-2923
Tenda AC6 fromDhcpListClient stack-based overflow
Published 2023-05-27 · Modified
9.8EPSS 0.010
CVE-2023-40837
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADD50' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADD50" function to execute commands.
Published 2023-08-30 · Modified
9.8EPSS 0.009
CVE-2023-38936
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
Published 2023-08-07 · Modified
9.8EPSS 0.009
CVE-2023-38933
Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38937
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38931
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-40846
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function sub_90998.
Published 2023-08-28 · Modified
9.8EPSS 0.008
CVE-2023-39670
Tenda AC6 _US_AC6V1.0BR_V15.03.05.16 was discovered to contain a buffer overflow via the function fgets.
Published 2023-08-18 · Modified
9.8EPSS 0.008
CVE-2025-25343
Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
Published 2025-02-12 · Modified
9.8EPSS 0.007
CVE-2025-32010
A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP response can lead to arbitrary code execution. An attacker can send an HTTP response to trigger this vulnerability.
Published 2025-08-20 · Modified
9.8EPSS 0.007
CVE-2023-40830
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
Published 2023-10-03 · Modified
9.8EPSS 0.007
CVE-2023-40845
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'sub_34FD0.' In the function, it reads user provided parameters and passes variables to the function without any length checks.
Published 2023-08-30 · Modified
9.8EPSS 0.007
CVE-2023-40844
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'formWifiBasicSet.'
Published 2023-08-30 · Modified
9.8EPSS 0.007
CVE-2023-40843
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "sub_73004."
Published 2023-08-30 · Modified
9.8EPSS 0.007
1 / 3Next →