VendorsTendaw15e_firmwareall versions
Vulnerabilities

Tenda W15E Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

31CVEs
CVE-2022-42058
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
Published 2022-11-15 · Modified
9.8EPSS 0.014
CVE-2023-27063
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2023-03-13 · Modified
9.8EPSS 0.010
CVE-2023-27061
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2023-03-13 · Modified
9.8EPSS 0.010
CVE-2024-4127
Tenda W15E guestWifiRuleRefresh stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.018
CVE-2024-4126
Tenda W15E SetSysTimeCfg formSetSysTime stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.018
CVE-2024-4125
Tenda W15E setStaticRoute formSetStaticRoute stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.018
CVE-2024-4124
Tenda W15E SetRemoteWebManage formSetRemoteWebManage stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2024-4123
Tenda W15E SetPortMapping formSetPortMapping stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2024-4122
Tenda W15E setDebugCfg formSetDebugCfg stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2024-4121
Tenda W15E formQOSRuleDel stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2024-4120
Tenda W15E modifyIpMacBind formIPMacBindModify stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2024-4119
Tenda W15E delIpMacBind formIPMacBindDel stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2024-4118
Tenda W15E addIpMacBind formIPMacBindAdd stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2024-4117
Tenda W15E DelPortMapping formDelPortMapping stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2024-4116
Tenda W15E DelDhcpRule formDelDhcpRule stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2024-4115
Tenda W15E AddDnsForward formAddDnsForward stack-based overflow
Published 2024-04-24 · Analyzed
9.0EPSS 0.017
CVE-2022-41395
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.
Published 2022-11-15 · Modified
7.8EPSS 0.014
CVE-2022-41396
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.
Published 2022-11-15 · Modified
7.8EPSS 0.014
CVE-2022-40847
In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerability allows attackers to run arbitrary commands on the server via the hostname parameter.
Published 2022-11-15 · Analyzed
7.8EPSS 0.010
CVE-2022-42053
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.
Published 2022-11-15 · Analyzed
7.8EPSS 0.010
CVE-2017-14514
Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a crafted URL.
Published 2017-09-17 · Modified
7.5EPSS 0.021
CVE-2017-14515
Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service (temporary HTTP outage and forced logout) via unspecified vectors.
Published 2017-09-17 · Modified
7.5EPSS 0.012
CVE-2022-42060
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.
Published 2022-11-15 · Modified
7.5EPSS 0.011
CVE-2023-27065
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2023-03-13 · Modified
7.5EPSS 0.009
CVE-2023-27064
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2023-03-13 · Modified
7.5EPSS 0.009
CVE-2023-27062
Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2023-03-13 · Modified
7.5EPSS 0.009
CVE-2026-30140
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive information disclosure and potential remote administrative access.
Published 2026-03-09 · Analyzed
7.5EPSS 0.003
CVE-2022-40845
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose sensitive information which they're not explicitly authorized to have.
Published 2022-11-15 · Analyzed
6.5EPSS 0.007
CVE-2022-40844
In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL body.
Published 2022-11-15 · Analyzed
5.4EPSS 0.006
CVE-2022-40843
The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. This leads to authenticated attackers having the ability to read the routers syslog.log file which contains the MD5 password of the Administrator's user account.
Published 2022-11-15 · Analyzed
4.9EPSS 0.288
CVE-2022-40846
In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.
Published 2022-11-15 · Analyzed
4.8EPSS 0.006