Tenda
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Tenda product.
RSS Feeds for Tenda security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Tenda products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Tenda Sorted by Most Security Vulnerabilities since 2018
Known Exploited Tenda Vulnerabilities
The following Tenda vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Tenda AC11 Up to 02.03.01.104_CN Stack Buffer Overflow |
Tenda AC11 devices with firmware through 02.03.01.104_CN contain a stack buffer overflow vulnerability in /goform/setmac which allows for arbitrary execution. CVE-2021-31755 Exploit Probability: 86.8% |
November 3, 2021 |
| Tenda Router Code Execution |
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter. CVE-2020-10987 Exploit Probability: 79.8% |
November 3, 2021 |
| Tenda Router Command Injection Vulnerability |
Issue on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. CVE-2018-14558 Exploit Probability: 8.7% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 302 vulnerabilities in Tenda with an average score of 8.4 out of ten. Last year, in 2025 Tenda had 372 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Tenda in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.10
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 302 | 8.41 |
| 2025 | 372 | 8.50 |
| 2024 | 405 | 8.94 |
| 2023 | 103 | 9.25 |
| 2022 | 187 | 8.38 |
| 2021 | 2 | 7.60 |
| 2020 | 2 | 8.65 |
It may take a day or so for new Tenda vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Tenda Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-82695 | Aug 31, 2026 |
Missing Auth in Tenda AC18 Telnet Handler v15.03.05.19A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-82694 | Aug 31, 2026 |
Tenda AC1206 15.03.06.23 WebUI R7WebsSecurityHandler Remote Auth BypassA vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-82693 | Aug 31, 2026 |
Tenda AC1206 15.03.06.23 Remote Missing Auth via Telnet UIA vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-82542 | Aug 30, 2026 |
Tenda HG10 Boa Web Server formIPv6Routing Buffer Overflow (CVE-2026-82542)A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-78141 | Aug 23, 2026 |
Command Injection in Tenda CH22 1.0.0.1 formexeCommandA vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-78063 | Aug 23, 2026 |
Tenda CH22 1.0.0.1 Command Injection via /goform/editFileNameA security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-77031 | Aug 20, 2026 |
Tenda CH22 1.0.0.1 formcreateFileName Cmd-Injection via fileNameMitA vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-19924 | Aug 16, 2026 |
Tenda AC10 16.03.10.09 Multi R7WebsSecurityHandler Auth Bypass CVE-2026-19924A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-19824 | Aug 14, 2026 |
Stack-based buffer overflow in Tenda W20E ipMacBindListStore (15.11.0.6)A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-19823 | Aug 14, 2026 |
Tenda W20E 15.11.0.6 Stack Buffer Overflow in QoS Rule DeletionA security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-19822 | Aug 14, 2026 |
Tenda W20E 15.11.0.6 QoS Edit buffer overflow (lstAdd)A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the argument qosListConnecttedNum leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-19821 | Aug 14, 2026 |
Tenda AC12 15.03.06.23_multi_TD01 httpd formSetRebootTimer Buffer OverflowA vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-19792 | Aug 14, 2026 |
Tenda G0 Router: Remote Buffer Overflow in httpd setPortMappingA security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-19791 | Aug 14, 2026 |
Remote Stack Overflow in Tenda G0 HTTPD Web UIA weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-19790 | Aug 14, 2026 |
Tenda G0 stack buffer overflow in web formSetPortMirrorA vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulation of the argument portMirrorMirroredPorts leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-19789 | Aug 14, 2026 |
Tenda AC1206 15.03.06.23 Multi_TD01: httpd Stack Buffer Overflow via set_wl_guest_iplistA vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-19788 | Aug 14, 2026 |
Tenda AC1206 15.03.06.23_multi_TD01: RCE stack-based overflow httpd set_dev_nameA vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-19750 | Aug 13, 2026 |
Tenda routers (CH/CP/TX3) SSH hardcoded password selfexploitableA flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used. |
And others... |
| CVE-2026-19749 | Aug 13, 2026 |
Tenda Router RTSP/ONVIF Auth Bypass RemoteA vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used. |
And others... |
| CVE-2026-19748 | Aug 13, 2026 |
Tenda Router Kylin WS: Insufficient Entropy in Session ParsingA security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. |
And others... |
| CVE-2026-19747 | Aug 13, 2026 |
Command Injection in Tenda ATE Module (CAte::HandleCmd)A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely. |
And others... |
| CVE-2026-19346 | Aug 09, 2026 |
Command Injection in Tenda CH22 1.0.0.1 CertListInfo (formCertListInfo)A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-16248 | Jul 20, 2026 |
Remote Stack Overflow in Tenda AC10 16.03.10.09 via httpd/netctrlA vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. |
|
| CVE-2026-15696 | Jul 14, 2026 |
Stack-based Buffer Overflow in Tenda BE12 Pro 16.03.66.23 (fromVirtualSer)A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-15695 | Jul 14, 2026 |
Stack Buffer Overflow in Tenda BE12 Pro 16.03.66.23 via DhcpListClientA flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-15694 | Jul 14, 2026 |
Tenda BE12 Pro <=16.03.66.23 Stackbased Buffer Overflow via /goform/SetIpBindA vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-15693 | Jul 14, 2026 |
Stack Buffer Overflow in BE12 Pro SafeMacFilter before 16.03.66.23A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-15692 | Jul 14, 2026 |
Tenda BE12 Pro stack-based buffer overflow, SafeUrlFilter (before 16.03.66.23)A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-15691 | Jul 14, 2026 |
Tenda BE12 Pro 16.03.66.23: Remote Stack-based Buffer Overflow in SafeClientFilterA security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-15543 | Jul 13, 2026 |
Remote Buffer Overflow in Tenda CH22 1.0.0.1 formCertListInfoA vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-11405 | Jul 06, 2026 |
Hidden Backdoor Auth via sys.rzadmin.password in httpdThe web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked any username works with the backdoor |
|
| CVE-2026-38142 | Jul 01, 2026 |
Tenda AC18 v15.03.05.05 Unauth Cmd Injection in fast_setting_internet_setAn unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to execute arbitrary commands via a crafted payload injected into the mac parameter. |
|
| CVE-2026-13519 | Jun 29, 2026 |
Tenda JD12L 16.03.53.23: Remote Stack BOverflow via NatStaticSettingA vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. |
|
| CVE-2026-13518 | Jun 29, 2026 |
Stack-Based Buffer Overflow in Tenda JD12L 16.03.53.23 via /goform/addressNatA vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-13517 | Jun 29, 2026 |
Stack Buffer Overflow in Tenda JD12L 16.03.53.23 formWifiBasicSet (security_5g)A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. |
|
| CVE-2026-13516 | Jun 28, 2026 |
Stack-based Buffer Overflow in Tenda JD12L 16.03.53.23 /goform/WifiGuestSetA vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. |
|
| CVE-2026-13515 | Jun 28, 2026 |
Tenda JD12L 16.03.53.23: formSetPPTPServer (SBO)A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-51843 | Jun 19, 2026 |
Tenda AC7 stack buffer overflow via wanMTU paramTenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. |
|
| CVE-2026-51844 | Jun 19, 2026 |
Tenda AC7 v15.03.06.44 Buffer Overflow via /goform/AdvSetMacMtuWan cloneTypeTenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. |
|
| CVE-2026-51845 | Jun 19, 2026 |
Tenda AC7 15.03.06.44 stack buffer overflow in AdvSetMacMtuWan via macTenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter. |
|
| CVE-2026-51846 | Jun 19, 2026 |
Tenda AC7 v15.03.06.44 RCE via WAN Speed Buffer OverflowIn Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution. |
|
| CVE-2026-11557 | Jun 08, 2026 |
Tenda F451 1.0.0.7/9 Natlimit stack buffer overflow (WebMgr)A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-11556 | Jun 08, 2026 |
Tenda F451 1.0.0.7/1.0.0.9 - OS Command Injection via formWriteFacMacA security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-11553 | Jun 08, 2026 |
Remote Stack Buffer Overflow in Tenda HG7HG9/HG10 via formPPPEdit encodenameA vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-11528 | Jun 08, 2026 |
Tenda AC18 15.03.05.05: Web Management Interface stack overflow via callbackA vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of the argument callback results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-11524 | Jun 08, 2026 |
Tenda W20E 15.11.0.6: Remote Stack-Buffer-Overflow in modifyWifiFilterRulesA vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The manipulation of the argument wifiFilterListRemark leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-11523 | Jun 08, 2026 |
Stack Overflow in Tenda W20E 15.11.0.6 WebMgr - formPortalAuth (gotoUrl)A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used. |
|
| CVE-2026-11522 | Jun 08, 2026 |
Tenda W20E 15.11.0.6 formSetPortMirror stack-based buffer overflowA vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used. |
|
| CVE-2026-11504 | Jun 08, 2026 |
Stack Buffer Overflow in Tenda CX12L 16.03.53.12 (WiFi Schedule setSchedWifi)A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration Endpoint. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. |
|
| CVE-2026-11503 | Jun 08, 2026 |
Tenda CX12L 16.03.53.12: Wi-Fi Config Buf Overflow via form_fast_setting_wifi_setA security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set of the component Wi-Fi Configuration Endpoint. Such manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. |
|