Tenda AC10 Firmware 16.03.10.20

CPE Details

Tenda AC10 Firmware 16.03.10.20
16.03.10.20
2024-08-05
11h07 +00:00
2024-08-05
11h07 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:o:tenda:ac10_firmware:16.03.10.20:*:*:*:*:*:*:*

Informations

Vendor

tenda

Product

ac10_firmware

Version

16.03.10.20

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-25454 2025-04-17 00h00 +00:00 Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
7.5
High
CVE-2025-25455 2025-04-17 00h00 +00:00 Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
7.5
High
CVE-2025-25457 2025-04-17 00h00 +00:00 Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.
7.5
High
CVE-2025-25453 2025-04-15 00h00 +00:00 Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.
4.6
Medium
CVE-2025-25456 2025-04-15 00h00 +00:00 Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
9.8
Critical
CVE-2025-25458 2025-04-15 00h00 +00:00 Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.
4.6
Medium
CVE-2024-10280 2024-10-23 13h31 +00:00 A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
7.1
High
CVE-2024-32317 2024-04-16 22h00 +00:00 Tenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.
7.5
High
CVE-2024-2856 2024-03-24 06h31 +00:00 A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257780. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
9.8
Critical
CVE-2024-25373 2024-02-14 23h00 +00:00 Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.
4.6
Medium