VendorsTendaac62.0
Vulnerabilities

Tenda AC6 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2023-38823
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
Published 2023-11-20 · Modified
9.8EPSS 0.012
CVE-2023-38936
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
Published 2023-08-07 · Modified
9.8EPSS 0.009
CVE-2023-38931
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38933
Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38937
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2024-52275
Denial of Service on Tenda AC6V2 Due To Stack Overflow
Published 2024-12-04 · Analyzed
9.8EPSS 0.006
CVE-2024-52714
Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
Published 2024-11-19 · Modified
9.8EPSS 0.006
CVE-2024-52274
Denial of Service on Tenda AC6V2 Due To Stack Overflow
Published 2024-12-04 · Analyzed
9.8EPSS 0.005
CVE-2024-52273
Denial of Service on Tenda AC6V2 Due To Stack Overflow
Published 2024-12-04 · Analyzed
9.8EPSS 0.005
CVE-2024-52272
Denial of Service on Tenda AC6V2 Due To Stack Overflow
Published 2024-12-04 · Analyzed
9.8EPSS 0.005
CVE-2025-12225
Tenda AC6 HTTP Request WifiGuestSet stack-based overflow
Published 2025-10-27 · Analyzed
9.0EPSS 0.009
CVE-2025-7914
Tenda AC6 httpd setparentcontrolinfo buffer overflow
Published 2025-07-21 · Analyzed
9.0EPSS 0.009
CVE-2026-8264
Tenda AC6 httpd WifiApScan formWifiApScan os command injection
Published 2026-05-11 · Analyzed
8.8EPSS 0.029
CVE-2024-51116
Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.
Published 2024-11-05 · Analyzed
8.8EPSS 0.004
CVE-2024-46450
Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.
Published 2025-01-16 · Analyzed
8.1EPSS 0.004
CVE-2020-28095
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
Published 2020-12-30 · Analyzed
7.8EPSS 0.012
CVE-2022-41485
Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47ce00 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2022-10-13 · Modified
7.5EPSS 0.009
CVE-2022-41483
Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x4a12cc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2022-10-13 · Modified
7.5EPSS 0.009
CVE-2022-41481
Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47de1c function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2022-10-13 · Modified
7.5EPSS 0.009
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2022-41480
Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x475dc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2022-10-13 · Modified
7.5EPSS 0.008
CVE-2022-41482
Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47c5dc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2022-10-13 · Modified
7.5EPSS 0.008
CVE-2025-60338
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.005
CVE-2025-70252
An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.
Published 2026-03-02 · Analyzed
7.5EPSS 0.004
CVE-2025-60342
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60337
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60339
Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the schedStartTime and schedEndTime parameters.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60340
Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60343
Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the wanMTU, wanSpeed, cloneType, mac, serviceName, serverName, wanMTU2, wanSpeed2, cloneType2, mac2, serviceName2, and serverName2 parameters.
Published 2025-10-22 · Analyzed
7.5EPSS 0.004
CVE-2025-55483
Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and deviceList.
Published 2025-08-20 · Analyzed
7.5EPSS 0.004
CVE-2025-55498
Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.
Published 2025-08-20 · Analyzed
7.5EPSS 0.004
CVE-2025-60341
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-55482
Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.
Published 2025-08-20 · Analyzed
7.5EPSS 0.004
CVE-2025-55503
Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.
Published 2025-08-20 · Analyzed
7.3EPSS 0.003
CVE-2026-8259
Tenda AC6 httpd telnet os command injection
Published 2026-05-11 · Analyzed
7.2EPSS 0.044
CVE-2026-8265
Tenda AC6 httpd getLogFile get_log_file os command injection
Published 2026-05-11 · Analyzed
7.2EPSS 0.044
CVE-2025-55499
Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.
Published 2025-08-20 · Analyzed
6.5EPSS 0.003