CVE-2026-104611
- EPSS 0.49%
- Veröffentlicht 02.10.2026 12:15:15
- Zuletzt bearbeitet 02.10.2026 14:17:09
A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based bu...
CVE-2026-86300
- EPSS 0.49%
- Veröffentlicht 07.09.2026 11:30:09
- Zuletzt bearbeitet 08.09.2026 16:18:27
A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been published an...
CVE-2026-6016
- EPSS 0.84%
- Veröffentlicht 10.04.2026 06:16:06
- Zuletzt bearbeitet 30.04.2026 13:59:44
A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer ov...
CVE-2026-6015
- EPSS 0.81%
- Veröffentlicht 10.04.2026 06:16:06
- Zuletzt bearbeitet 30.04.2026 14:03:13
A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflo...
CVE-2026-2192
- EPSS 0.66%
- Veröffentlicht 08.02.2026 23:15:49
- Zuletzt bearbeitet 10.02.2026 15:09:48
A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the argument sys.schedulereboot.start_time/sys.schedulereboot.end_time leads to stack-b...
CVE-2026-2191
- EPSS 0.66%
- Veröffentlicht 08.02.2026 22:32:10
- Zuletzt bearbeitet 10.02.2026 15:09:59
A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-based buffer overflow. The attack may be initiated remotely. The exploit ...
CVE-2025-14286
- EPSS 0.66%
- Veröffentlicht 09.12.2025 01:32:07
- Zuletzt bearbeitet 07.10.2026 20:10:01
A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosur...
CVE-2025-57638
- EPSS 0.37%
- Veröffentlicht 23.09.2025 19:15:41
- Zuletzt bearbeitet 25.09.2025 16:09:10
Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.
CVE-2025-57639
- EPSS 0.98%
- Veröffentlicht 23.09.2025 18:15:35
- Zuletzt bearbeitet 25.09.2025 16:09:17
OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file.
CVE-2025-10443
- EPSS 4.02%
- Veröffentlicht 15.09.2025 11:32:07
- Zuletzt bearbeitet 19.09.2025 19:22:53
A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to buffer overflow. The attack can b...