Skip to main content

Daily materialized evidence profile

Vendor tenda

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
1,846
CVEs with mentions
645
Total mentions
2,403
CVEs with KEV
3
CVEs with PoC
407

Attack vector counts

Network
1,716
Adjacent network
99
Local
31
Physical
0

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2020-10987

Published Jul 13, 2020

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
58.5
KEV listed

CVE-2021-31755

Published May 7, 2021

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
46.0
KEV listed

CVE-2026-5339

Published Apr 2, 2026

A vulnerability was detected in Tenda G103 1.0.0.5. The impacted element is the function action_set_net_settings of the file gpon.lua of the component Setting Handler. Performing…

CVSS 2.0 · Low
evidence mentions
12
Buzz score
41.6
Public PoC observed

CVE-2025-12595

Published Nov 2, 2025

A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /goform/SetVirtualServerCfg. This manipulation of the argument li…

CVSS 7.4 · High
evidence mentions
6
Buzz score
40.5
Public PoC observed

CVE-2025-12596

Published Nov 2, 2025

A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation o…

CVSS 7.4 · High
evidence mentions
6
Buzz score
40.5
Public PoC observed