VendorsTendaac6any version
Vulnerabilities

Tenda AC6 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

42CVEs
CVE-2022-25450
Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.116
CVE-2022-25445
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.
Published 2022-03-18 · Modified
10.0EPSS 0.090
CVE-2022-25453
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25454
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25455
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25461
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25460
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25447
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25452
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25456
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25457
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25448
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25449
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25446
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25451
Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25458
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2022-25459
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.
Published 2022-03-18 · Modified
10.0EPSS 0.017
CVE-2024-10697
Tenda AC6 API Endpoint WriteFacMac formWriteFacMac command injection
Published 2024-11-02 · Modified
9.8EPSS 0.262
CVE-2025-0349
Tenda AC6 GetParentControlInfo stack-based overflow
Published 2025-01-09 · Modified
9.8EPSS 0.018
CVE-2024-10698
Tenda AC6 SetOnlineDevName formSetDeviceName stack-based overflow
Published 2024-11-02 · Analyzed
9.8EPSS 0.013
CVE-2025-1814
Tenda AC6 WifiExtraSet stack-based overflow
Published 2025-03-02 · Analyzed
9.8EPSS 0.010
CVE-2023-2923
Tenda AC6 fromDhcpListClient stack-based overflow
Published 2023-05-27 · Modified
9.8EPSS 0.010
CVE-2025-25343
Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
Published 2025-02-12 · Modified
9.8EPSS 0.007
CVE-2023-40830
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
Published 2023-10-03 · Modified
9.8EPSS 0.007
CVE-2025-29031
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.
Published 2025-03-14 · Modified
9.8EPSS 0.005
CVE-2025-29029
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
Published 2025-03-14 · Modified
9.8EPSS 0.005
CVE-2025-29030
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.
Published 2025-03-14 · Modified
9.8EPSS 0.005
CVE-2025-50258
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.
Published 2025-07-03 · Analyzed
8.1EPSS 0.004
CVE-2025-50263
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.
Published 2025-07-03 · Analyzed
8.1EPSS 0.004
CVE-2023-26976
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
Published 2023-04-04 · Modified
7.5EPSS 0.159
CVE-2022-41485
Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47ce00 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2022-10-13 · Modified
7.5EPSS 0.009
CVE-2025-46035
Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated HTTP GET request to the /goform/openSchedWifi endpoint
Published 2025-06-12 · Modified
7.5EPSS 0.006
CVE-2025-29121
A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.
Published 2025-03-20 · Analyzed
7.5EPSS 0.005
CVE-2025-50260
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.
Published 2025-07-03 · Analyzed
7.5EPSS 0.004
CVE-2025-50262
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.
Published 2025-07-03 · Analyzed
7.5EPSS 0.004
CVE-2025-50528
A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.
Published 2025-06-27 · Analyzed
7.3EPSS 0.004
CVE-2025-57296
Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the list and vlanId parameters, the sub_ADBC0 helper function concatenates these user-supplied values into nvram set system commands using doSystemCmd, without validating or sanitizing special characters (e.g., ;, ", #). An unauthenticated or authenticated attacker can exploit this by submitting a crafted POST request, leading to arbitrary system command execution on the affected device.
Published 2025-09-19 · Analyzed
6.5EPSS 0.033
CVE-2025-25507
There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.
Published 2025-02-21 · Analyzed
6.5EPSS 0.005
CVE-2025-50641
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId.
Published 2025-07-01 · Modified
6.5EPSS 0.004
CVE-2025-25505
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.
Published 2025-02-21 · Analyzed
6.5EPSS 0.003
1 / 2Next →