Tenda / AC18
32 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-82695 | Tenda AC18 Telnet telnet missing authentication | CRITICAL | 10.0 | Aug 31, 2026 |
| CVE-2026-11528 | Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow | HIGH | 8.7 | Jun 8, 2026 |
| CVE-2025-14993 | Tenda AC18 HTTP Request SetDlnaCfg sprintf stack-based overflow | HIGH | 8.7 | Dec 21, 2025 |
| CVE-2025-14992 | Tenda AC18 HTTP Request GetParentControlInfo strcpy stack-based overflow | HIGH | 8.7 | Dec 21, 2025 |
| CVE-2025-11328 | Tenda AC18 SetDDNSCfg stack-based overflow | HIGH | 8.7 | Oct 6, 2025 |
| CVE-2025-11327 | Tenda AC18 SetUpnpCfg stack-based overflow | HIGH | 8.7 | Oct 6, 2025 |
| CVE-2025-11326 | Tenda AC18 WifiMacFilterSet stack-based overflow | HIGH | 8.7 | Oct 6, 2025 |
| CVE-2025-11325 | Tenda AC18 fast_setting_pppoe_set stack-based overflow | HIGH | 8.7 | Oct 6, 2025 |
| CVE-2025-11324 | Tenda AC18 setNotUpgrade stack-based overflow | HIGH | 8.7 | Oct 6, 2025 |
| CVE-2025-11123 | Tenda AC18 saveAutoQos stack-based overflow | HIGH | 8.7 | Sep 28, 2025 |
| CVE-2025-11122 | Tenda AC18 WizardHandle stack-based overflow | HIGH | 8.7 | Sep 28, 2025 |
| CVE-2025-11121 | Tenda AC18 AdvSetLanip command injection | MEDIUM | 5.3 | Sep 28, 2025 |
| CVE-2025-9023 | Tenda AC7/AC18 SetLEDCfg formSetSchedLed buffer overflow | HIGH | 8.7 | Aug 15, 2025 |
| CVE-2025-8182 | Tenda AC18 Samba smb.conf weak password | MEDIUM | 6.3 | Jul 26, 2025 |
| CVE-2025-5609 | Tenda AC18 AdvSetLanip fromadvsetlanip buffer overflow | HIGH | 8.7 | Jun 4, 2025 |
| CVE-2025-5608 | Tenda AC18 SetSysAutoRebbotCfg formsetreboottimer buffer overflow | HIGH | 8.7 | Jun 4, 2025 |
| CVE-2025-5607 | Tenda AC18 setPptpUserList formSetPPTPUserList buffer overflow | HIGH | 8.7 | Jun 4, 2025 |
| CVE-2025-5606 | Tenda AC18 SetIPTVCfg formSetIptv command injection | MEDIUM | 5.3 | Jun 4, 2025 |
| CVE-2025-0528 | Tenda AC8/AC10/AC18 HTTP Request telnet command injection | HIGH | 8.6 | Jan 17, 2025 |
| CVE-2024-10280 | Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference | HIGH | 7.1 | Oct 23, 2024 |
| CVE-2024-41630 | Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/f… | HIGH | 7.6 | Jul 31, 2024 |
| CVE-2024-33180 | Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo. | CRITICAL | 9.8 | Jul 16, 2024 |
| CVE-2024-34974 | Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter. | HIGH | 8.2 | May 10, 2024 |
| CVE-2024-33835 | Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function. | CRITICAL | 9.8 | May 1, 2024 |
| CVE-2024-2854 | Tenda AC18 setsambacfg formSetSambaConf os command injection | CRITICAL | 9.8 | Mar 24, 2024 |
Showing 1 to 25 of 32 CVEs