CVE-2025-45428
- EPSS 0.86%
- Veröffentlicht 23.04.2025 00:00:00
- Zuletzt bearbeitet 30.04.2025 16:12:11
In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-45427
- EPSS 0.86%
- Veröffentlicht 23.04.2025 00:00:00
- Zuletzt bearbeitet 30.04.2025 13:51:20
In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29387
- EPSS 0.55%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 17.03.2025 19:51:04
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29384
- EPSS 1.91%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 19.03.2025 19:15:49
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29385
- EPSS 0.88%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 19.03.2025 19:15:49
In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29386
- EPSS 0.88%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 19.03.2025 19:15:49
In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-22949
- EPSS 1.93%
- Veröffentlicht 10.01.2025 16:15:31
- Zuletzt bearbeitet 09.04.2025 18:36:01
Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.
CVE-2025-22946
- EPSS 0.9%
- Veröffentlicht 10.01.2025 15:15:16
- Zuletzt bearbeitet 09.04.2025 18:35:44
Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.
CVE-2024-10280
- EPSS 0.81%
- Veröffentlicht 23.10.2024 14:15:04
- Zuletzt bearbeitet 01.11.2024 14:03:20
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argu...
CVE-2024-42634
- EPSS 2.21%
- Veröffentlicht 16.08.2024 16:15:06
- Zuletzt bearbeitet 11.04.2025 15:13:25
A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.