VendorsTendaac7any version
Vulnerabilities

Tenda AC7 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2018-14558
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.
Published 2018-10-30 · Analyzed
10.0KEVEPSS 0.087
CVE-2025-1819
Tenda AC7 1200M telnet TendaTelnet os command injection
Published 2025-03-02 · Analyzed
9.8EPSS 0.018
CVE-2018-18729
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy to a variable placed on the heap, which can leak sensitive information or even hijack program control flow.
Published 2018-10-28 · Modified
9.8EPSS 0.013
CVE-2023-37716
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting.
Published 2023-07-14 · Modified
9.8EPSS 0.009
CVE-2023-37717
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient.
Published 2023-07-14 · Modified
9.8EPSS 0.009
CVE-2023-37714
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromRouteStatic.
Published 2023-07-14 · Modified
9.8EPSS 0.009
CVE-2026-51846
In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.
Published 2026-06-19 · Analyzed
9.8EPSS 0.008
CVE-2026-51845
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.
Published 2026-06-19 · Analyzed
9.8EPSS 0.006
CVE-2026-51844
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.
Published 2026-06-19 · Analyzed
9.8EPSS 0.006
CVE-2026-51843
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.
Published 2026-06-19 · Analyzed
9.8EPSS 0.006
CVE-2025-3346
Tenda AC7 SetPptpServerCfg formSetPPTPServer buffer overflow
Published 2025-04-07 · Analyzed
9.0EPSS 0.077
CVE-2024-2896
Tenda AC7 WifiWpsStart formWifiWpsStart stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.019
CVE-2024-2903
Tenda AC7 GetParentControlInfo stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.018
CVE-2024-2902
Tenda AC7 WifiGuestSet fromSetWifiGusetBasic stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.018
CVE-2024-2893
Tenda AC7 SetOnlineDevName formSetDeviceName stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.017
CVE-2024-2892
Tenda AC7 setcfm formSetCfm stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.017
CVE-2024-2898
Tenda AC7 SetStaticRouteCfg fromSetRouteStatic stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.017
CVE-2024-2895
Tenda AC7 WifiWpsOOB formWifiWpsOOB stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.017
CVE-2024-2899
Tenda AC7 WifiExtraSet fromSetWirelessRepeat stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.017
CVE-2024-2900
Tenda AC7 saveParentControlInfo stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.017
CVE-2024-2901
Tenda AC7 openSchedWifi setSchedWifi stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.017
CVE-2024-2891
Tenda AC7 QuickIndex formQuickIndex stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.017
CVE-2024-2894
Tenda AC7 SetNetControlList formSetQosBand stack-based overflow
Published 2024-03-26 · Analyzed
9.0EPSS 0.016
CVE-2025-4809
Tenda AC7 setMacFilterCfg fromSafeSetMacFilter stack-based overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.013
CVE-2025-1851
Tenda AC7 SetFirewallCfg formSetFirewallCfg stack-based overflow
Published 2025-03-03 · Analyzed
9.0EPSS 0.011
CVE-2025-4810
Tenda AC7 SetRebootTimer formSetRebootTimer stack-based overflow
Published 2025-05-16 · Analyzed
9.0EPSS 0.010
CVE-2025-9023
Tenda AC7/AC18 SetLEDCfg formSetSchedLed buffer overflow
Published 2025-08-15 · Analyzed
9.0EPSS 0.008
CVE-2024-2897
Tenda AC7 WriteFacMac formWriteFacMac os command injection
Published 2024-03-26 · Analyzed
8.8EPSS 0.078
CVE-2024-48825
Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
Published 2024-10-28 · Analyzed
8.8EPSS 0.017
CVE-2024-48826
Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
Published 2024-10-28 · Analyzed
8.8EPSS 0.017
CVE-2026-24441
Tenda AC7 Transmits Admin Credentials Without HTTPS Protection
Published 2026-02-03 · Analyzed
8.2EPSS 0.002
CVE-2018-14557
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, a causing buffer overflow.
Published 2019-04-25 · Modified
7.8EPSS 0.014
CVE-2018-14559
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.
Published 2019-04-25 · Modified
7.8EPSS 0.014
CVE-2018-18708
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.014
CVE-2018-18727
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18706
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18707
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-27 · Modified
7.8EPSS 0.011
CVE-2018-18730
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18731
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2018-18732
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
1 / 2Next →