Vulnerabilities
Vulnerable Software
Tenda:  Security Vulnerabilities
A vulnerability was found in Tenda AC8 16.03.34.06. It has been declared as critical. Affected by this vulnerability is the function compare_parentcontrol_time of the file /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This is not the same issue like CVE-2023-33671. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
8.7
EPSS Score
0.01
Published
2024-10-18
Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root
CVSS Score
8.0
EPSS Score
0.004
Published
2024-10-17
A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
5.3
EPSS Score
0.225
Published
2024-10-10
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.
CVSS Score
9.8
EPSS Score
0.006
Published
2024-09-20
Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.
CVSS Score
9.8
EPSS Score
0.006
Published
2024-09-13
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.
CVSS Score
9.8
EPSS Score
0.006
Published
2024-09-13
Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.
CVSS Score
7.5
EPSS Score
0.006
Published
2024-09-13
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
CVSS Score
9.8
EPSS Score
0.105
Published
2024-09-13
Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.
CVSS Score
9.8
EPSS Score
0.006
Published
2024-09-13
CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.
CVSS Score
9.8
EPSS Score
0.006
Published
2024-09-13


Contact Us

Shodan ® - All rights reserved