VendorsTendaac9all versions
Vulnerabilities

Tenda AC9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

92CVEs
CVE-2018-18730
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
Published 2018-10-28 · Modified
7.8EPSS 0.011
CVE-2024-10280
Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
Published 2024-10-23 · Analyzed
7.5EPSS 0.008
CVE-2025-57638
Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.
Published 2025-09-23 · Analyzed
7.5EPSS 0.004
CVE-2022-36570
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.
Published 2022-08-31 · Modified
7.2EPSS 0.011
CVE-2022-36571
Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.
Published 2022-08-31 · Modified
7.2EPSS 0.011
CVE-2025-29387
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
Published 2025-03-14 · Analyzed
7.1EPSS 0.006
CVE-2025-5900
Tenda AC9 cross-site request forgery
Published 2025-06-09 · Analyzed
7.1EPSS 0.003
CVE-2025-9731
Tenda AC9 Administrative shadow hard-coded credentials
Published 2025-08-31 · Analyzed
7.0EPSS 0.001
CVE-2025-5836
Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection
Published 2025-06-07 · Analyzed
6.5EPSS 0.027
CVE-2017-16936
Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to read arbitrary files via a cgi-bin/luci/request?op=1&path= URI that uses directory traversal sequences after a /usb/ substring.
Published 2017-11-24 · Modified
6.5EPSS 0.010
CVE-2025-57639
OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file.
Published 2025-09-23 · Analyzed
6.5EPSS 0.010
CVE-2021-42659
There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long list parameter occurs.
Published 2022-05-24 · Modified
6.5EPSS 0.008
← Prev3 / 3