
CVE-2022-42166
https://notcve.org/view.php?id=CVE-2022-42166
17 Oct 2022 — Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan. Tenda AC10 versión V15.03.06.23, contiene una vulnerabilidad de desbordamiento de pila por medio de /goform/formSetSpeedWan • https://github.com/z1r00/IOT_Vul/blob/main/Tenda/AC10/formSetSpeedWan/readme.md • CWE-787: Out-of-bounds Write •

CVE-2022-42167
https://notcve.org/view.php?id=CVE-2022-42167
17 Oct 2022 — Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg. Tenda AC10 versión V15.03.06.23, contiene una vulnerabilidad de desbordamiento de pila por medio de /goform/formSetFirewallCfg • https://github.com/z1r00/IOT_Vul/blob/main/Tenda/AC10/formSetFirewallCfg/readme.md • CWE-787: Out-of-bounds Write •

CVE-2022-42168
https://notcve.org/view.php?id=CVE-2022-42168
17 Oct 2022 — Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind. Tenda AC10 versión V15.03.06.23, contiene una vulnerabilidad de desbordamiento de pila por medio de /goform/fromSetIpMacBind • https://github.com/z1r00/IOT_Vul/blob/main/Tenda/AC10/fromSetIpMacBind/readme.md • CWE-787: Out-of-bounds Write •

CVE-2022-42169
https://notcve.org/view.php?id=CVE-2022-42169
17 Oct 2022 — Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter. Tenda AC10 versión V15.03.06.23, contiene una vulnerabilidad de desbordamiento de pila por medio de /goform/addWifiMacFilter • https://github.com/z1r00/IOT_Vul/blob/main/Tenda/AC10/addWifiMacFilter/readme.md • CWE-787: Out-of-bounds Write •

CVE-2022-42170
https://notcve.org/view.php?id=CVE-2022-42170
17 Oct 2022 — Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart. Tenda AC10 versión V15.03.06.23, contiene una vulnerabilidad de desbordamiento de pila por medio de /goform/formWifiWpsStart • https://github.com/z1r00/IOT_Vul/blob/main/Tenda/AC10/formWifiWpsStart/readme.md • CWE-787: Out-of-bounds Write •

CVE-2022-42171
https://notcve.org/view.php?id=CVE-2022-42171
17 Oct 2022 — Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo. Tenda AC10 versión V15.03.06.23, contiene una vulnerabilidad de desbordamiento de pila por medio de /goform/saveParentControlInfo • https://github.com/z1r00/IOT_Vul/blob/main/Tenda/AC10/saveParentControlInfo/readme.md • CWE-787: Out-of-bounds Write •

CVE-2022-32054
https://notcve.org/view.php?id=CVE-2022-32054
07 Jul 2022 — Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter. Se ha detectado que Tenda AC10 versión US_AC10V1.0RTL_V15.03.06.26_multi_TD01 contiene una vulnerabilidad de ejecución de código remota (RCE) por medio del parámetro lanIp • https://github.com/winmt/CVE/blob/main/Tenda%20AC10/README.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2018-14559
https://notcve.org/view.php?id=CVE-2018-14559
25 Apr 2019 — An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow. Se de... • https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-02/Tenda.md • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2018-14557
https://notcve.org/view.php?id=CVE-2018-14557
25 Apr 2019 — An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the page parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, a causing buffer overflow. Se de... • https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-03/Tenda.md • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2018-14558 – Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
https://notcve.org/view.php?id=CVE-2018-14558
30 Oct 2018 — An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Se ha descubierto un problema en dispositivos Tenda AC7 con firmwa... • https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-01/Tenda.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •