Ax1806 Firmware Tenda Ax1806 Firmware

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Tenda Ax1806 Firmware.

By the Year

In 2026 there have been 0 vulnerabilities in Tenda Ax1806 Firmware. Ax1806 Firmware did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 24 9.62
2023 2 9.10

It may take a day or so for new Ax1806 Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Tenda Ax1806 Firmware Security Vulnerabilities

Tenda AX1806 v1.0.0.1 Stack Overflow via iptv.stb.mode
CVE-2024-44557 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.

Memory Corruption

Tenda AX1806 v1.0.0.1 Stack Overflow via iptv.city.vlan Param
CVE-2024-44555 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.

Memory Corruption

Stack Overflow via iptv.stb.mode in Tenda AX1806 v1.0.0.1
CVE-2024-44553 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

Memory Corruption

Stack Overflow in Tenda AX1806 v1.0.0.1 via adv.iptv.stballvlans
CVE-2024-44552 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.

Memory Corruption

Tenda AX1806 v1.0.0.1 Stack Overflow via iptv.city.vlan
CVE-2024-44551 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.

Memory Corruption

Tenda AX1806 v1.0.0.1 Stack Overflow via adv.iptv.stbpvid in formGetIptv
CVE-2024-44550 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

Memory Corruption

Stack Overflow via iptv.stb.port in Tenda AX1806 v1.0.0.1
CVE-2024-44549 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.

Memory Corruption

Tenda AX1806 v1.0.0.1 Stack Overflow via adv.iptv.stbalvlans in setIptvInfo
CVE-2024-44556 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.

Memory Corruption

Tenda AX1806 v1.0.0.1 Stack Overflow via adv.iptv.stbpvid
CVE-2024-44558 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.

Memory Corruption

Tenda AX1806 v1.0.0.1 stack overflow via serverName param
CVE-2024-44565 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.

Memory Corruption

Stack Overflow in Tenda AX1806 v1.0.0.1 IPTV setIptvInfo (port)
CVE-2024-44563 9.8 - Critical - August 26, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.

Memory Corruption

Tenda AX1806 Stack Overflow DoS v1.0.0.1
CVE-2024-41492 - July 19, 2024

A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

StackOverflow in /goform/SetStaticRouteCfg of Tenda AX1806 1.0.0.1
CVE-2024-40415 9.8 - Critical - July 15, 2024

A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Memory Corruption

Tenda AX1806 1.0.0.1 stack-based buffer overflow in /goform/SetVirtualServerCfg
CVE-2024-40416 9.8 - Critical - July 15, 2024

A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Memory Corruption

Tenda AX1806 1.0.0.1: Stack Buffer Overflow in /goform/SetNetControlList
CVE-2024-40414 9.8 - Critical - July 15, 2024

A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Memory Corruption

Tenda AX1806 1.0.0.1: Stack Buffer Overflow via formSetRebootTimer
CVE-2024-40417 - July 10, 2024

A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow.

Tenda AX1806 stack overflow via adv.iptv.stbpvid (v1.0.0.1)
CVE-2024-35580 - May 20, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

Tenda AX1806 v1.0.0.1 Stack Overflow via iptv.city.vlan in formSetIptv
CVE-2024-35579 - May 20, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.

Tenda AX1806 1.0.0.1 Stack Overflow via adv.iptv.stballvlans parameter
CVE-2024-35578 - May 20, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

Stack Overflow in Tenda AX1806 v1.0.0.1 via iptv.stb.port
CVE-2024-35576 - May 20, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.

Stack Overflow in Tenda AX1806 v1.0.0.1 via iptv.stb.mode param
CVE-2024-35571 - May 20, 2024

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

Tenda AX1806 1.0.0.1 Stack Buffer Overflow in SetRebootTimer
CVE-2024-4239 8.8 - High - April 26, 2024

A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-262130 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Memory Corruption

Tenda AX1806 1.0.0.1 Remote Stack Overflow in formSetDeviceName
CVE-2024-4238 8.8 - High - April 26, 2024

A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262129 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Memory Corruption

Critical stack-overflow in Tenda AX1806 1.0.0.1 R7WebsSecurityHandler
CVE-2024-4237 8.8 - High - April 26, 2024

A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262128. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Memory Corruption

Tenda AX1806 V1.0.0.1 Stack Overflow via sub_455D4 in fromSetWirelessRepeat
CVE-2023-47456 9.1 - Critical - November 07, 2023

Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat.

Memory Corruption

Tenda AX1806 V1.0.0.1 Heap Overflow in setSchedWifi Func
CVE-2023-47455 9.1 - Critical - November 07, 2023

Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.

Memory Corruption

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Tenda Ax1806 Firmware or by Tenda? Click the Watch button to subscribe.

Tenda
Vendor

subscribe