Skip to main content

Vendor/product archive

tenda / ac9 CVEs

Beta · best-effort

92 CVEs tagged to tenda / ac956 Critical, 29 High, 3 Medium, 4 Low, 0 Unrated.

CVE-2026-6016

Published Apr 10, 2026

A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performi…

CVSS 7.4 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-6015

Published Apr 10, 2026

A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipul…

CVSS 7.4 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-2192

Published Feb 8, 2026

A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the argument sys…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-2191

Published Feb 8, 2026

A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-ba…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-57639

Published Sep 23, 2025

OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf func…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9731

Published Aug 31, 2025

A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This man…

CVSS 1.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5900

Published Jun 9, 2025

A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5839

Published Jun 7, 2025

A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5836

Published Jun 7, 2025

A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-44877

Published May 2, 2025

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-44872

Published May 2, 2025

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attack…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-45429

Published Apr 23, 2025

In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-45428

Published Apr 23, 2025

In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-45427

Published Apr 23, 2025

In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code exec…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-29387

Published Mar 14, 2025

In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29386

Published Mar 14, 2025

In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-29385

Published Mar 14, 2025

In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-29384

Published Mar 14, 2025

In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-22949

Published Jan 10, 2025

Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22946

Published Jan 10, 2025

Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 92 CVEsPage 1 of 4