CVE-2025-10442
- EPSS 8.32%
- Veröffentlicht 15.09.2025 11:15:33
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is po...
- EPSS 0.14%
- Veröffentlicht 31.08.2025 13:32:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials. It is possible to launch the a...
CVE-2025-5900
- EPSS 0.27%
- Veröffentlicht 09.06.2025 22:00:19
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclos...
CVE-2025-5847
- EPSS 0.82%
- Veröffentlicht 08.06.2025 13:31:44
- Zuletzt bearbeitet 09.06.2025 19:04:55
A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation o...
CVE-2025-5839
- EPSS 0.85%
- Veröffentlicht 07.06.2025 17:31:13
- Zuletzt bearbeitet 09.06.2025 19:07:34
A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument...
CVE-2025-5836
- EPSS 2.7%
- Veröffentlicht 07.06.2025 13:31:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to comman...
CVE-2025-45042
- EPSS 1.61%
- Veröffentlicht 05.05.2025 00:00:00
- Zuletzt bearbeitet 07.05.2025 16:39:20
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
CVE-2025-44877
- EPSS 1.81%
- Veröffentlicht 02.05.2025 00:00:00
- Zuletzt bearbeitet 27.05.2025 14:21:50
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44872
- EPSS 1.81%
- Veröffentlicht 02.05.2025 00:00:00
- Zuletzt bearbeitet 27.05.2025 14:21:40
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-45429
- EPSS 1%
- Veröffentlicht 23.04.2025 00:00:00
- Zuletzt bearbeitet 30.04.2025 15:48:51
In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.