VendorsTendaac7all versions
Vulnerabilities

Tenda AC7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

72CVEs
CVE-2024-2899
Tenda AC7 WifiExtraSet fromSetWirelessRepeat stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.017
CVE-2024-2894
Tenda AC7 SetNetControlList formSetQosBand stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.016
CVE-2025-4809
Tenda AC7 setMacFilterCfg fromSafeSetMacFilter stack-based overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.013
CVE-2025-1851
Tenda AC7 SetFirewallCfg formSetFirewallCfg stack-based overflow
Published 2025-03-03 · Analyzed
9.0EPSS 0.011
CVE-2025-11525
Tenda AC7 SetUpnpCfg stack-based overflow
Published 2025-10-09 · Analyzed
9.0EPSS 0.010
CVE-2025-4810
Tenda AC7 SetRebootTimer formSetRebootTimer stack-based overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.010
CVE-2025-11524
Tenda AC7 SetDDNSCfg stack-based overflow
Published 2025-10-09 · Analyzed
9.0EPSS 0.010
CVE-2025-9023
Tenda AC7/AC18 SetLEDCfg formSetSchedLed buffer overflow
Published 2025-08-15 · Analyzed
9.0EPSS 0.008
CVE-2025-11526
Tenda AC7 WifiMacFilterSet stack-based overflow
Published 2025-10-09 · Modified
9.0EPSS 0.008
CVE-2025-11528
Tenda AC7 saveAutoQos stack-based overflow
Published 2025-10-09 · Analyzed
9.0EPSS 0.008
CVE-2025-11527
Tenda AC7 fast_setting_pppoe_set stack-based overflow
Published 2025-10-09 · Modified
9.0EPSS 0.008
CVE-2026-4974
Tenda AC7 POST Request SetSysTimeCfg fromSetSysTime memory corruption
Published 2026-03-27 · Analyzed
9.0EPSS 0.006
CVE-2024-2897
Tenda AC7 WriteFacMac formWriteFacMac os command injection
Published 2024-03-26 · Analyzed
8.8EPSS 0.078
CVE-2025-11523
Tenda AC7 AdvSetLanip command injection
Published 2025-10-09 · Analyzed
8.8EPSS 0.037
CVE-2024-32281
Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.
Published 2024-04-17 · Analyzed
8.8EPSS 0.018
CVE-2024-48826
Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
Published 2024-10-28 · Analyzed
8.8EPSS 0.017
CVE-2024-48825
Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
Published 2024-10-28 · Analyzed
8.8EPSS 0.017
CVE-2026-24441
Tenda AC7 Transmits Admin Credentials Without HTTPS Protection
Published 2026-02-03 · Analyzed
8.2EPSS 0.002
CVE-2018-14557
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, a causing buffer overflow.
Published 2019-04-25 · Modified
7.8EPSS 0.014
CVE-2018-14559
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.
Published 2019-04-25 · Modified
7.8EPSS 0.014
CVE-2018-18708
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.014
CVE-2018-18707
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18709
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18706
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18731
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18727
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18730
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18732
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2026-24427
Tenda AC7 Exposes Admin Credentials in Configuration Responses
Published 2026-02-03 · Analyzed
6.8EPSS 0.001
CVE-2026-24434
Tenda AC7 Web Interface Lacks CSRF Protections for Admin Actions
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2026-24426
Tenda AC7 Reflected XSS via Web Interface Output Encoding
Published 2026-02-03 · Analyzed
6.1EPSS 0.002
← Prev2 / 2