Skip to main content

Vendor archive

tenda CVEs

Beta · best-effort

1,846 CVEs tagged to vendor tenda551 Critical, 1,064 High, 194 Medium, 37 Low, 0 Unrated.

CVE-2025-70648

Published Jan 21, 2026

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function. This vulnerability allows attackers to cause a Denial of S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70646

Published Jan 21, 2026

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. This vulnerability allows attackers to cause a Denial of Serv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70644

Published Jan 21, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This vulnerability allows attackers to cause a Denial of Service…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70651

Published Jan 21, 2026

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70650

Published Jan 21, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetMacFilterCfg function. This vulnerability allows attackers to cause a D…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70645

Published Jan 21, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilterCfg function. This vulnerability allows attackers to cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71020

Published Jan 16, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. This vulnerability allows attackers to cause a Denial of Ser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70746

Published Jan 16, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime function. This vulnerability allows attackers to cause a Denial o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70656

Published Jan 15, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71019

Published Jan 15, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Ser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70744

Published Jan 15, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71021

Published Jan 14, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function. This vulnerability allows attackers to cause a Denial of S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70747

Published Jan 14, 2026

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serviceName parameter of the sub_65A28 function. This vulnerability allows attackers to cause a Denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71027

Published Jan 13, 2026

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71026

Published Jan 13, 2026

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71025

Published Jan 13, 2026

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71024

Published Jan 13, 2026

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-71023

Published Jan 13, 2026

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the mac2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Den…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-0640

Published Jan 6, 2026

A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2026-0581

Published Jan 5, 2026

A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd.…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-15356

Published Dec 30, 2025

A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file /goform/PowerSaveSet. The manipulation of the argument powe…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-15255

Published Dec 30, 2025

A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHandler. Executing a manipulatio…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2025-15254

Published Dec 30, 2025

A vulnerability was found in Tenda W6-S 1.0.0.4(510). This affects the function TendaAte of the file /goform/ate of the component ATE Service. Performing a manipulation results in…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 251-275 of 1,846 CVEsPage 11 of 74