CVE-2025-5839
- EPSS 0.2%
- Veröffentlicht 07.06.2025 17:31:13
- Zuletzt bearbeitet 09.06.2025 19:07:34
A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument...
CVE-2025-5836
- EPSS 2.05%
- Veröffentlicht 07.06.2025 13:31:06
- Zuletzt bearbeitet 09.06.2025 19:07:49
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to comman...
CVE-2025-45042
- EPSS 14.83%
- Veröffentlicht 05.05.2025 00:00:00
- Zuletzt bearbeitet 07.05.2025 16:39:20
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
CVE-2025-44877
- EPSS 12.51%
- Veröffentlicht 02.05.2025 00:00:00
- Zuletzt bearbeitet 27.05.2025 14:21:50
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44872
- EPSS 12.51%
- Veröffentlicht 02.05.2025 00:00:00
- Zuletzt bearbeitet 27.05.2025 14:21:40
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-45429
- EPSS 2.44%
- Veröffentlicht 23.04.2025 00:00:00
- Zuletzt bearbeitet 30.04.2025 15:48:51
In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.
CVE-2025-45428
- EPSS 2.25%
- Veröffentlicht 23.04.2025 00:00:00
- Zuletzt bearbeitet 30.04.2025 16:12:11
In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-45427
- EPSS 2.25%
- Veröffentlicht 23.04.2025 00:00:00
- Zuletzt bearbeitet 30.04.2025 13:51:20
In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29384
- EPSS 14.63%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 19.03.2025 19:15:49
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29385
- EPSS 1.13%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 19.03.2025 19:15:49
In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.