CVE-2024-10280 – Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference
https://notcve.org/view.php?id=CVE-2024-10280
23 Oct 2024 — A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. • https://github.com/JohenanLi/router_vuls/blob/main/websReadEvent/websReadEvent.md • CWE-476: NULL Pointer Dereference •
CVE-2024-32316
https://notcve.org/view.php?id=CVE-2024-32316
17 Apr 2024 — Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function. El firmware Tenda AC500 V2.0.1.9(1307) tiene una vulnerabilidad de desbordamiento de pila en la función fromDhcpListClient. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC500/fromDhcpListClient_list1.md • CWE-121: Stack-based Buffer Overflow •
CVE-2024-32318
https://notcve.org/view.php?id=CVE-2024-32318
17 Apr 2024 — Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function. El firmware Tenda AC500 V2.0.1.9(1307) tiene una vulnerabilidad de desbordamiento de pila a través del parámetro vlan en la función formSetVlanInfo. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC500/fromSetVlanInfo_vlan.md • CWE-121: Stack-based Buffer Overflow •
CVE-2023-25233
https://notcve.org/view.php?id=CVE-2023-25233
27 Feb 2023 — Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface. • https://github.com/Funcy33/Vluninfo_Repo/tree/main/CNVDs/113 • CWE-787: Out-of-bounds Write •
CVE-2023-25234
https://notcve.org/view.php?id=CVE-2023-25234
27 Feb 2023 — Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface. • https://github.com/FzBacon/CVE-2023-25234_Tenda_AC6_stack_overflow • CWE-787: Out-of-bounds Write •
CVE-2023-25235
https://notcve.org/view.php?id=CVE-2023-25235
27 Feb 2023 — Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid. • https://github.com/Funcy33/Vluninfo_Repo/tree/main/CNVDs/113_2 • CWE-787: Out-of-bounds Write •