CVE-2024-10662
- EPSS 0.61%
- Veröffentlicht 01.11.2024 16:15:07
- Zuletzt bearbeitet 05.11.2024 14:30:16
A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The...
CVE-2024-10661
- EPSS 0.61%
- Veröffentlicht 01.11.2024 16:15:07
- Zuletzt bearbeitet 05.11.2024 14:30:37
A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation of the argument scanList leads to stack-based buffer overflow. Th...
CVE-2024-10280
- EPSS 0.22%
- Veröffentlicht 23.10.2024 14:15:04
- Zuletzt bearbeitet 01.11.2024 14:03:20
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argu...
CVE-2023-36103
- EPSS 12.8%
- Veröffentlicht 10.09.2024 16:15:18
- Zuletzt bearbeitet 24.09.2024 18:10:16
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
- EPSS 0.13%
- Veröffentlicht 17.04.2024 16:15:08
- Zuletzt bearbeitet 30.06.2025 13:37:14
Tenda AC15 v15.03.20_multi, v15.03.05.19, and v15.03.05.18 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
CVE-2024-30840
- EPSS 0.04%
- Veröffentlicht 15.04.2024 20:15:11
- Zuletzt bearbeitet 14.04.2025 13:40:27
A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.
- EPSS 0.24%
- Veröffentlicht 29.03.2024 16:15:11
- Zuletzt bearbeitet 08.04.2025 15:27:52
Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.
CVE-2024-30613
- EPSS 0.17%
- Veröffentlicht 29.03.2024 13:15:15
- Zuletzt bearbeitet 08.04.2025 15:27:30
Tenda AC15 v15.03.05.18 has a stack overflow vulnerability in the time parameter from the setSmartPowerManagement function.
CVE-2024-2855
- EPSS 0.13%
- Veröffentlicht 24.03.2024 06:15:11
- Zuletzt bearbeitet 21.11.2024 09:10:41
A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20. Affected by this vulnerability is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument time leads to stack-bas...
CVE-2024-2852
- EPSS 0.13%
- Veröffentlicht 24.03.2024 05:15:09
- Zuletzt bearbeitet 21.11.2024 09:10:40
A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-ba...