Tenda AC6

CPE Details

Tenda AC6
-
2022-03-24
23h43 +00:00
2022-09-29
13h01 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:h:tenda:ac6:-:*:*:*:*:*:*:*

Informations

Vendor

tenda

Product

ac6

Version

-

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2025-29121 2025-03-20 00h00 +00:00 A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.
7.5
Haute
CVE-2025-29029 2025-03-14 00h00 +00:00 Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
9.8
Critique
CVE-2025-29030 2025-03-14 00h00 +00:00 Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.
9.8
Critique
CVE-2025-29031 2025-03-14 00h00 +00:00 Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.
9.8
Critique
CVE-2025-25505 2025-02-21 00h00 +00:00 Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.
6.5
Moyen
CVE-2025-25507 2025-02-21 00h00 +00:00 There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.
6.5
Moyen
CVE-2025-25343 2025-02-12 00h00 +00:00 Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
9.8
Critique
CVE-2025-0349 2025-01-09 10h31 +00:00 A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src/mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
8.7
Haute
CVE-2024-10698 2024-11-02 13h31 +00:00 A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
8.7
Haute
CVE-2024-10697 2024-11-02 12h00 +00:00 A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument mac leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
5.3
Moyen
CVE-2023-40830 2023-10-03 00h00 +00:00 Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.
9.8
Critique
CVE-2022-40010 2023-06-25 22h00 +00:00 Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vulnerability via the deviceId parameter in the Parental Control module.
5.4
Moyen
CVE-2023-2923 2023-05-27 07h31 +00:00 A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability is the function fromDhcpListClient. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-230077 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
9.8
Critique
CVE-2023-26976 2023-04-04 00h00 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
7.5
Haute
CVE-2022-41485 2022-10-12 22h00 +00:00 Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47ce00 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
7.5
Haute
CVE-2022-25460 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the endip parameter in the SetPptpServerCfg function.
9.8
Critique
CVE-2022-25461 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the startip parameter in the SetPptpServerCfg function.
9.8
Critique
CVE-2022-25459 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the S1 parameter in the SetSysTimeCfg function.
9.8
Critique
CVE-2022-25458 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the cmdinput parameter in the exeCommand function.
9.8
Critique
CVE-2022-25457 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function.
9.8
Critique
CVE-2022-25455 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
9.8
Critique
CVE-2022-25456 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the security_5g parameter in the WifiBasicSet function.
9.8
Critique
CVE-2022-25454 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the loginpwd parameter in the SetFirewallCfg function.
9.8
Critique
CVE-2022-25452 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the URLs parameter in the saveParentControlInfo function.
9.8
Critique
CVE-2022-25453 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.
9.8
Critique
CVE-2022-25451 2022-03-18 19h53 +00:00 Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the setstaticroutecfg function.
9.8
Critique
CVE-2022-25449 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.
9.8
Critique
CVE-2022-25450 2022-03-18 19h53 +00:00 Tenda AC6 V15.03.05.09_multi was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function.
9.8
Critique
CVE-2022-25448 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the day parameter in the openSchedWifi function.
9.8
Critique
CVE-2022-25446 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSchedWifi function.
9.8
Critique
CVE-2022-25447 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi function.
9.8
Critique
CVE-2022-25445 2022-03-18 19h53 +00:00 Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.
9.8
Critique