CVE-2026-2192
- EPSS 0.09%
- Veröffentlicht 08.02.2026 23:15:49
- Zuletzt bearbeitet 10.02.2026 15:09:48
A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the argument sys.schedulereboot.start_time/sys.schedulereboot.end_time leads to stack-b...
CVE-2026-2191
- EPSS 0.09%
- Veröffentlicht 08.02.2026 22:32:10
- Zuletzt bearbeitet 10.02.2026 15:09:59
A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-based buffer overflow. The attack may be initiated remotely. The exploit ...
CVE-2025-14286
- EPSS 0.06%
- Veröffentlicht 09.12.2025 01:32:07
- Zuletzt bearbeitet 11.12.2025 17:15:12
A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosur...
CVE-2025-10443
- EPSS 0.48%
- Veröffentlicht 15.09.2025 11:32:07
- Zuletzt bearbeitet 19.09.2025 19:22:53
A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to buffer overflow. The attack can b...
CVE-2025-10442
- EPSS 0.37%
- Veröffentlicht 15.09.2025 11:15:33
- Zuletzt bearbeitet 19.09.2025 20:39:12
A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is po...
- EPSS 0.01%
- Veröffentlicht 31.08.2025 13:32:07
- Zuletzt bearbeitet 04.09.2025 16:49:00
A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials. It is possible to launch the a...
CVE-2025-5900
- EPSS 0.05%
- Veröffentlicht 09.06.2025 22:00:19
- Zuletzt bearbeitet 16.06.2025 14:42:41
A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclos...
CVE-2025-5847
- EPSS 0.22%
- Veröffentlicht 08.06.2025 13:31:44
- Zuletzt bearbeitet 09.06.2025 19:04:55
A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation o...
CVE-2025-5839
- EPSS 0.2%
- Veröffentlicht 07.06.2025 17:31:13
- Zuletzt bearbeitet 09.06.2025 19:07:34
A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument...
CVE-2025-5836
- EPSS 2.05%
- Veröffentlicht 07.06.2025 13:31:06
- Zuletzt bearbeitet 09.06.2025 19:07:49
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to comman...