VendorsTendaac71.0
Vulnerabilities

Tenda AC7 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2025-5861
Tenda AC7 AdvSetLanip fromadvsetlanip buffer overflow
Published 2025-06-09 · Analyzed
9.8EPSS 0.068
CVE-2023-41556
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetIpMacBind.
Published 2023-08-30 · Modified
9.8EPSS 0.011
CVE-2025-29135
A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.
Published 2025-03-24 · Analyzed
9.8EPSS 0.011
CVE-2025-5862
Tenda AC7 setPptpUserList formSetPPTPUserList buffer overflow
Published 2025-06-09 · Analyzed
9.8EPSS 0.010
CVE-2025-11586
Tenda AC7 setNotUpgrade stack-based overflow
Published 2025-10-10 · Analyzed
9.8EPSS 0.009
CVE-2023-38936
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
Published 2023-08-07 · Modified
9.8EPSS 0.009
CVE-2023-41557
Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-38930
Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-41562
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-41559
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-41558
Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter timeZone at url /goform/SetSysTimeCfg.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-41555
Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-41552
Tenda AC7 V1.0 V15.03.06.44 and Tenda AC9 V3.0 V15.03.06.42_multi were discovered to contain a stack overflow via parameter ssid at url /goform/fast_setting_wifi_set.
Published 2023-08-30 · Modified
9.8EPSS 0.008
CVE-2023-38937
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38933
Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2023-38931
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
Published 2023-08-07 · Modified
9.8EPSS 0.008
CVE-2024-32301
Tenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.
Published 2024-04-17 · Analyzed
9.8EPSS 0.008
CVE-2025-29137
Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.
Published 2025-03-19 · Analyzed
9.8EPSS 0.005
CVE-2025-8017
Tenda AC7 httpd setMacFilterCfg formSetMacFilterCfg stack-based overflow
Published 2025-07-22 · Analyzed
9.0EPSS 0.104
CVE-2025-11525
Tenda AC7 SetUpnpCfg stack-based overflow
Published 2025-10-09 · Analyzed
9.0EPSS 0.010
CVE-2025-11524
Tenda AC7 SetDDNSCfg stack-based overflow
Published 2025-10-09 · Analyzed
9.0EPSS 0.010
CVE-2025-11526
Tenda AC7 WifiMacFilterSet stack-based overflow
Published 2025-10-09 · Modified
9.0EPSS 0.008
CVE-2025-11527
Tenda AC7 fast_setting_pppoe_set stack-based overflow
Published 2025-10-09 · Modified
9.0EPSS 0.008
CVE-2025-11528
Tenda AC7 saveAutoQos stack-based overflow
Published 2025-10-09 · Analyzed
9.0EPSS 0.008
CVE-2026-4974
Tenda AC7 POST Request SetSysTimeCfg fromSetSysTime memory corruption
Published 2026-03-27 · Analyzed
9.0EPSS 0.006
CVE-2025-11523
Tenda AC7 AdvSetLanip command injection
Published 2025-10-09 · Analyzed
8.8EPSS 0.037
CVE-2024-32281
Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.
Published 2024-04-17 · Analyzed
8.8EPSS 0.018