VendorsTendaac6_firmware15.03.05.19
Vulnerabilities

Tenda ac6 Firmware 15.03.05.19

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-10697
Tenda AC6 API Endpoint WriteFacMac formWriteFacMac command injection
Published 2024-11-02 · Modified
9.8EPSS 0.262
CVE-2024-10698
Tenda AC6 SetOnlineDevName formSetDeviceName stack-based overflow
Published 2024-11-02 · Analyzed
9.8EPSS 0.013
CVE-2023-40830
Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
Published 2023-10-03 · Modified
9.8EPSS 0.007
CVE-2022-45640
Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).
Published 2022-12-01 · Modified
7.5EPSS 0.010
CVE-2022-45641
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Buffer Overflow via formSetMacFilterCfg.
Published 2022-12-02 · Modified
7.5EPSS 0.008
CVE-2025-57296
Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the list and vlanId parameters, the sub_ADBC0 helper function concatenates these user-supplied values into nvram set system commands using doSystemCmd, without validating or sanitizing special characters (e.g., ;, ", #). An unauthenticated or authenticated attacker can exploit this by submitting a crafted POST request, leading to arbitrary system command execution on the affected device.
Published 2025-09-19 · Analyzed
6.5EPSS 0.033
CVE-2022-45673
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
Published 2022-12-02 · Modified
6.5EPSS 0.003
CVE-2022-45674
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
Published 2022-12-02 · Modified
6.5EPSS 0.003