Tenda Tenda

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Tenda product.

RSS Feeds for Tenda security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Tenda products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Tenda Sorted by Most Security Vulnerabilities since 2018

Tenda Ac1865 vulnerabilities

Tenda Ac18 Firmware64 vulnerabilities

Tenda Ac10 Firmware54 vulnerabilities

Tenda Fh1202 Firmware49 vulnerabilities

Tenda W30e Firmware48 vulnerabilities

Tenda Ac6 Firmware46 vulnerabilities

Tenda Ac1544 vulnerabilities

Tenda Ac15 Firmware40 vulnerabilities

Tenda Ac8 Firmware40 vulnerabilities

Tenda Ac7 Firmware39 vulnerabilities

Tenda Ch22 Firmware39 vulnerabilities

Tenda Fh1206 Firmware37 vulnerabilities

Tenda Ax1803 Firmware36 vulnerabilities

Tenda Ac732 vulnerabilities

Tenda Ac9 Firmware30 vulnerabilities

Tenda W15e Firmware28 vulnerabilities

Tenda F1203 Firmware28 vulnerabilities

Tenda Fh451 Firmware27 vulnerabilities

Tenda Ax1806 Firmware26 vulnerabilities

Tenda F453 Firmware25 vulnerabilities

Tenda Ac5 Firmware24 vulnerabilities

Tenda Fh1205 Firmware24 vulnerabilities

Tenda Fh1201 Firmware23 vulnerabilities

Tenda W20e Firmware22 vulnerabilities

Tenda Wh450 Firmware21 vulnerabilities

Tenda Fh1203 Firmware21 vulnerabilities

Tenda F451 Firmware20 vulnerabilities

Tenda O3 Firmware20 vulnerabilities

Tenda A15 Firmware19 vulnerabilities

Tenda I21 Firmware19 vulnerabilities

Tenda Ac23 Firmware18 vulnerabilities

Tenda Ch2218 vulnerabilities

Tenda Ac1206 Firmware16 vulnerabilities

Tenda I22 Firmware16 vulnerabilities

Tenda Ac10u Firmware15 vulnerabilities

Tenda Ac500 Firmware15 vulnerabilities

Tenda Ax12 Firmware14 vulnerabilities

Tenda F1202 Firmware14 vulnerabilities

Tenda W18e Firmware14 vulnerabilities

Tenda Rx3 Firmware13 vulnerabilities

Tenda Tx3 Firmware13 vulnerabilities

Tenda Ac20 Firmware12 vulnerabilities

Tenda Cp3 Firmware12 vulnerabilities

Tenda Ac21 Firmware11 vulnerabilities

Tenda Rx2 Pro Firmware11 vulnerabilities

Tenda W6 S Firmware10 vulnerabilities

Tenda Hg10 Firmware10 vulnerabilities

Tenda I9 Firmware10 vulnerabilities

Tenda I12 Firmware9 vulnerabilities

Tenda M3 Firmware9 vulnerabilities

Tenda W12 Firmware8 vulnerabilities

Tenda 4g300 Firmware7 vulnerabilities

Tenda W9 Firmware7 vulnerabilities

Tenda Be12 Pro6 vulnerabilities

Tenda G3 Firmware6 vulnerabilities

Tenda O36 vulnerabilities

Tenda A18 Firmware5 vulnerabilities

Tenda Ac6v2 0 Firmware5 vulnerabilities

Tenda G103 Firmware5 vulnerabilities

Tenda Jd12l5 vulnerabilities

Tenda Tx9 Pro Firmware5 vulnerabilities

Tenda Rx9 Pro Firmware5 vulnerabilities

Tenda Ac8v4 Firmware4 vulnerabilities

Tenda Ax3 Firmware4 vulnerabilities

Tenda F3 Firmware4 vulnerabilities

Tenda O6 Firmware4 vulnerabilities

Tenda Ch103 vulnerabilities

Tenda Ch73 vulnerabilities

Tenda Ch7g3 vulnerabilities

Tenda Cp33 vulnerabilities

Tenda Cp3 Pro3 vulnerabilities

Tenda Cp73 vulnerabilities

Tenda Cx12l Firmware3 vulnerabilities

Tenda G03 vulnerabilities

Tenda Hg103 vulnerabilities

Tenda Hg7hg93 vulnerabilities

Tenda I3 Firmware3 vulnerabilities

Tenda Tc3b14c3 vulnerabilities

Tenda Tc3b15c3 vulnerabilities

Tenda Tc3t14c3 vulnerabilities

Tenda Tc3t15c3 vulnerabilities

Tenda Tx9 Firmware3 vulnerabilities

Tenda Cp3 Pro Firmware2 vulnerabilities

Tenda W122 vulnerabilities

Tenda I29 Firmware2 vulnerabilities

Tenda N301 Firmware2 vulnerabilities

Tenda O1 Firmware2 vulnerabilities

Tenda Ac10v4 Firmware1 vulnerability

Tenda Ac11 Firmware1 vulnerability

Tenda Ac12061 vulnerability

Tenda Ac231 vulnerability

Tenda Ac61 vulnerability

Tenda Ax2 Pro Firmware1 vulnerability

Tenda Ax9 Firmware1 vulnerability

Tenda Cp1 vulnerability

Tenda I12 Framework1 vulnerability

Tenda I24 Firmware1 vulnerability

Tenda N3001 vulnerability

Tenda N300 Firmware1 vulnerability

Known Exploited Tenda Vulnerabilities

The following Tenda vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Tenda AC11 Up to 02.03.01.104_CN Stack Buffer Overflow Tenda AC11 devices with firmware through 02.03.01.104_CN contain a stack buffer overflow vulnerability in /goform/setmac which allows for arbitrary execution.
CVE-2021-31755 Exploit Probability: 86.9%
November 3, 2021
Tenda Router Code Execution The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
CVE-2020-10987 Exploit Probability: 79.8%
November 3, 2021
Tenda Router Command Injection Vulnerability Issue on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.
CVE-2018-14558 Exploit Probability: 8.7%
November 3, 2021

Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 316 vulnerabilities in Tenda with an average score of 8.4 out of ten. Last year, in 2025 Tenda had 372 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Tenda in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.09




Year Vulnerabilities Average Score
2026 316 8.42
2025 372 8.50
2024 405 8.94
2023 103 9.25
2022 187 8.38
2021 2 7.60
2020 2 8.65

It may take a day or so for new Tenda vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Tenda Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-90689 Sep 14, 2026
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
W20e Firmware
CVE-2026-90688 Sep 14, 2026
A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overflow. It is possible to launch the attack remotely.
W20e Firmware
CVE-2026-86300 Sep 07, 2026
Tenda AC9 15.03.05.14 Improper Auth via R7WebsSecurityHandler (Remote) A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published and may be used.
Ac9 Firmware
CVE-2026-86167 Sep 06, 2026
OS Command Injection in Tenda HG10's Boa formgponConf via fmgpon_loid A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Hg10 Firmware
CVE-2026-86166 Sep 06, 2026
Tenda HG10 BoaWS Buffer Overflow via formWanRedirect A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Hg10 Firmware
CVE-2026-86165 Sep 06, 2026
Tenda HG10 Buffer Overflow in formURL Function (Remote Exploit) A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.
Hg10 Firmware
CVE-2026-86153 Sep 06, 2026
Tenda CP3 27.5.57.101 Privilege hop via CRedirSrv::SetRedirect (Remote) A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.
Cp3 Firmware
CVE-2026-86152 Sep 06, 2026
Remote OS Command Injection in Tenda CP3 27.5.57.101 CAutoAddWifi A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
Cp3 Firmware
CVE-2026-86151 Sep 05, 2026
Tenda CP3 27.5.57.101 CMD Injection via Network Config API A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.
Cp3 Firmware
CVE-2026-86150 Sep 05, 2026
Hard-coded credentials via hostapd wpa_passphrase in Tenda CP3 27.5.57.101 A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Cp3 Firmware
CVE-2026-86149 Sep 05, 2026
Tenda CP3 27.5.57.101 Remote OS Command Injection via NetCheckPing A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
Cp3 Firmware
CVE-2026-86148 Sep 05, 2026
OS Command Injection in Tenda CP3 Kylin SystemAsh Before 27.5.57.101 A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
Cp3 Firmware
CVE-2026-85110 Sep 03, 2026
Tenda HG10 Boa Web Server ssid Buffer Overflow (CVE-2026-85110) A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Hg10 Firmware
CVE-2026-85109 Sep 03, 2026
Boa Web Server Buffer Overflow in Tenda HG10 Login A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Hg10 Firmware
CVE-2026-82695 Aug 31, 2026
Missing Auth in Tenda AC18 Telnet Handler v15.03.05.19 A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Ac18 Firmware
CVE-2026-82694 Aug 31, 2026
Tenda AC1206 15.03.06.23 WebUI R7WebsSecurityHandler Remote Auth Bypass A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
Ac1206 Firmware
CVE-2026-82693 Aug 31, 2026
Tenda AC1206 15.03.06.23 Remote Missing Auth via Telnet UI A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Ac1206 Firmware
CVE-2026-82542 Aug 30, 2026
Tenda HG10 Boa Web Server formIPv6Routing Buffer Overflow (CVE-2026-82542) A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Hg10 Firmware
CVE-2026-78141 Aug 23, 2026
Command Injection in Tenda CH22 1.0.0.1 formexeCommand A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Ch22 Firmware
CVE-2026-78063 Aug 23, 2026
Tenda CH22 1.0.0.1 Command Injection via /goform/editFileName A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Ch22 Firmware
CVE-2026-77031 Aug 20, 2026
Tenda CH22 1.0.0.1 formcreateFileName Cmd-Injection via fileNameMit A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Ch22 Firmware
CVE-2026-19924 Aug 16, 2026
Tenda AC10 16.03.10.09 Multi R7WebsSecurityHandler Auth Bypass CVE-2026-19924 A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Ac10 Firmware
CVE-2026-19824 Aug 14, 2026
Stack-based buffer overflow in Tenda W20E ipMacBindListStore (15.11.0.6) A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
W20e Firmware
CVE-2026-19823 Aug 14, 2026
Tenda W20E 15.11.0.6 Stack Buffer Overflow in QoS Rule Deletion A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
W20e Firmware
CVE-2026-19822 Aug 14, 2026
Tenda W20E 15.11.0.6 QoS Edit buffer overflow (lstAdd) A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the argument qosListConnecttedNum leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.
W20e Firmware
CVE-2026-19821 Aug 14, 2026
Tenda AC12 15.03.06.23_multi_TD01 httpd formSetRebootTimer Buffer Overflow A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Ac12
CVE-2026-19792 Aug 14, 2026
Tenda G0 Router: Remote Buffer Overflow in httpd setPortMapping A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
G0
CVE-2026-19791 Aug 14, 2026
Remote Stack Overflow in Tenda G0 HTTPD Web UI A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
G0
CVE-2026-19790 Aug 14, 2026
Tenda G0 stack buffer overflow in web formSetPortMirror A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulation of the argument portMirrorMirroredPorts leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
G0
CVE-2026-19789 Aug 14, 2026
Tenda AC1206 15.03.06.23 Multi_TD01: httpd Stack Buffer Overflow via set_wl_guest_iplist A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Ac1206 Firmware
CVE-2026-19788 Aug 14, 2026
Tenda AC1206 15.03.06.23_multi_TD01: RCE stack-based overflow httpd set_dev_name A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
Ac1206 Firmware
CVE-2026-19750 Aug 13, 2026
Tenda routers (CH/CP/TX3) SSH hardcoded password selfexploitable A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used.
Ch
Cp
Tx3
And others...
CVE-2026-19749 Aug 13, 2026
Tenda Router RTSP/ONVIF Auth Bypass Remote A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.
Ch7
Ch7g
Ch10
And others...
CVE-2026-19748 Aug 13, 2026
Tenda Router Kylin WS: Insufficient Entropy in Session Parsing A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to insufficient entropy. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult.
Ch7
Ch7g
Ch10
And others...
CVE-2026-19747 Aug 13, 2026
Command Injection in Tenda ATE Module (CAte::HandleCmd) A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.
Ch7
Ch7g
Ch10
And others...
CVE-2026-19346 Aug 09, 2026
Command Injection in Tenda CH22 1.0.0.1 CertListInfo (formCertListInfo) A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Ch22 Firmware
CVE-2026-16248 Jul 20, 2026
Remote Stack Overflow in Tenda AC10 16.03.10.09 via httpd/netctrl A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
Ac10 Firmware
CVE-2026-15696 Jul 14, 2026
Stack-based Buffer Overflow in Tenda BE12 Pro 16.03.66.23 (fromVirtualSer) A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Be12 Pro
CVE-2026-15695 Jul 14, 2026
Stack Buffer Overflow in Tenda BE12 Pro 16.03.66.23 via DhcpListClient A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.
Be12 Pro
CVE-2026-15694 Jul 14, 2026
Tenda BE12 Pro <=16.03.66.23 Stackbased Buffer Overflow via /goform/SetIpBind A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.
Be12 Pro
CVE-2026-15693 Jul 14, 2026
Stack Buffer Overflow in BE12 Pro SafeMacFilter before 16.03.66.23 A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Be12 Pro
CVE-2026-15692 Jul 14, 2026
Tenda BE12 Pro stack-based buffer overflow, SafeUrlFilter (before 16.03.66.23) A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Be12 Pro
CVE-2026-15691 Jul 14, 2026
Tenda BE12 Pro 16.03.66.23: Remote Stack-based Buffer Overflow in SafeClientFilter A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Be12 Pro
CVE-2026-15543 Jul 13, 2026
Remote Buffer Overflow in Tenda CH22 1.0.0.1 formCertListInfo A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Ch22 Firmware
CVE-2026-11405 Jul 06, 2026
Hidden Backdoor Auth via sys.rzadmin.password in httpd The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked any username works with the backdoor
CVE-2026-38142 Jul 01, 2026
Tenda AC18 v15.03.05.05 Unauth Cmd Injection in fast_setting_internet_set An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to execute arbitrary commands via a crafted payload injected into the mac parameter.
Ac18
CVE-2026-13519 Jun 29, 2026
Tenda JD12L 16.03.53.23: Remote Stack BOverflow via NatStaticSetting A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
Jd12l
CVE-2026-13518 Jun 29, 2026
Stack-Based Buffer Overflow in Tenda JD12L 16.03.53.23 via /goform/addressNat A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Jd12l
CVE-2026-13517 Jun 29, 2026
Stack Buffer Overflow in Tenda JD12L 16.03.53.23 formWifiBasicSet (security_5g) A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.
Jd12l
CVE-2026-13516 Jun 28, 2026
Stack-based Buffer Overflow in Tenda JD12L 16.03.53.23 /goform/WifiGuestSet A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
Jd12l
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.