PatchSiren

Tenda CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Tenda CVE published 2026-08-09

CVE-2026-19346

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T10:17:10.567Z and has not been modified since then. The vulnerability affects Tenda CH22 1.0.0.1, specifically the formCertListInfo function, allowing for command injection via the Name argument. The attack can be initiated remotely. Evidence is limited to public sources and may not reflect the f [truncated]

CRITICAL Tenda CVE published 2026-07-31

CVE-2026-67822

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T17:16:35.210Z and has not been modified since then. Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without le [truncated]

HIGH Tenda CVE published 2026-07-20

CVE-2026-16248

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01, affecting the function fromAdvSetLanip of the file /goform/AdvSetLanip in the httpd/netctrl component. The manipulation of the GetValue/SetValue arguments results in a stack-based buffer overflow. The attack may be performed remotely. This issue has a CVSS score of 7.4 and is classified as HIGH. Evidence is limited; verify affected scope and [truncated]

CRITICAL Tenda CVE published 2026-07-15

CVE-2026-51380

A Buffer Overflow vulnerability exists in Tenda AC10 v3 (firmware V03.03.16.09). The vulnerability is located in the /cgi-bin/UploadCfg endpoint and could allow attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code. The CVSS score for this vulnerability is 9.8, indicating a Critical severity level. This vulnerability can be exploited by attackers to disrupt the service [truncated]

HIGH Tenda CVE published 2026-07-13

CVE-2026-15543

A HIGH severity vulnerability was found in Tenda CH22 1.0.0.1, affecting the formCertListInfo function. The vulnerability is a buffer overflow caused by manipulation of the Name argument, allowing for remote attacks. The CVE record was published on 2026-07-13T08:16:20.967Z and has not been modified since then. The CVSS score is 7.4, and administrators and users of Tenda CH22 1.0.0.1 should be aware of thi [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51606

CVE-2026-51606 is a HIGH severity vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). The vulnerability causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across mul [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51605

CVE-2026-51605 is a stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991). An unauthenticated remote attacker can cause a denial of service via a crafted TEARDOWN request. This vulnerability has a high impact on network availability and requires immediate attention from users of the affected product.

HIGH Tenda CVE published 2026-07-09

CVE-2026-51604

CVE-2026-51604 is a stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). An unauthenticated remote attacker can cause a denial of service via a crafted PLAY request. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. This type of vulnerability can be used to disrupt service, and defenders should be cautious of potential impact on network ava [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51603

CVE-2026-51603 is a stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). An unauthenticated remote attacker can cause a denial of service via a crafted second SETUP request. To exploit this, the attacker must first complete OPTIONS, DESCRIBE, and a legitimate first SETUP request to obtain a valid session ID. The RTSP service's second-stage URL routing pars [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51602

A stack-based buffer overflow vulnerability exists in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). An unauthenticated remote attacker can cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the first SETUP request. This issue allows an attacker to supply a crafted URL that can trigger a stac [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51601

CVE-2026-51601 is a stack-based buffer overflow vulnerability in Tenda CP3 V3.0 firmware V31.1.9.91. The RTSP service fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker can send a PLAY request with an excessively long clock= value to cause the RTSP service to crash. This vulnerability has a high impact on affected s [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51600

The Tenda CP3 V3.0 firmware V31.1.9.91 is vulnerable to a denial-of-service condition due to improper handling of RTSP requests. Specifically, the device does not validate the Content-Length header field in RTSP requests, including DESCRIBE, SETUP, and PLAY methods. When a request with a Content-Length header is received without a corresponding message body, the RTSP parser enters a persistent body-awaiti [truncated]

CRITICAL Tenda CVE published 2026-07-06

CVE-2026-11405

A hidden backdoor authentication mechanism was discovered in the web server binary /bin/httpd. This backdoor, located in the login() function, allows for admin-level access without proper authentication. The backdoor reads a password from the device configuration and compares it directly to the user-supplied password, granting admin access if they match.

HIGH Tenda CVE published 2026-06-29

CVE-2026-13519

A stack-based buffer overflow vulnerability was found in Tenda JD12L 16.03.53.23. The issue impacts the fromNatStaticSetting function of the /goform/NatStaticSetting file. The vulnerability can be exploited remotely by manipulating the page argument. The exploit has been made public and could potentially be used in attacks. Users of the affected product should apply patches or mitigations as soon as avail [truncated]

HIGH Tenda CVE published 2026-06-29

CVE-2026-13516

CVE-2026-13516 is a stack-based buffer overflow vulnerability detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in the vulnerability. The attack may be initiated remotely. The exploit is now public and may be used. This vulnerability has a CVSS score of 7.4 and a sev [truncated]

CRITICAL Tenda CVE published 2026-06-19

CVE-2026-51846

CVE-2026-51846 is a stack buffer overflow vulnerability in the Tenda AC7 router, specifically in the wanSpeed parameter of the /goform/AdvSetMacMtuWan route. This vulnerability, present in version 15.03.06.44, could allow for remote arbitrary code execution. The CVE was published on June 19, 2026. Given the potential for remote code execution, defenders should prioritize patching or mitigating this vulner [truncated]

CRITICAL Tenda CVE published 2026-06-19

CVE-2026-51845

CVE-2026-51845 is a stack buffer overflow vulnerability in Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the mac parameter. Defenders should assess exposure and prioritize patching due to potential remote exploitation. The CVE was published on 2026-06-19 and has not been assessed for CVSS score or severity. Limited information is available, emphasizing the n [truncated]

CRITICAL Tenda CVE published 2026-06-19

CVE-2026-51844

CVE-2026-51844 is a stack buffer overflow vulnerability in Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. This issue may allow attackers to execute arbitrary code. Affected users should review and apply patches from the vendor. The CVE was published on 2026-06-19 and has not been modified since then. The vulnerability's severity and s [truncated]

CRITICAL Tenda CVE published 2026-06-19

CVE-2026-51843

CVE-2026-51843 is a stack buffer overflow vulnerability in Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. This issue may allow attackers to execute arbitrary code. Affected users should review and apply patches from the vendor. The CVE was published on 2026-06-19 and has not been modified since then. The vulnerability's severity and impa [truncated]

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38065

CVE-2026-38065 is a command injection vulnerability in Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_ims_on_with_apn via the ims_apn parameter. This CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-38065) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-38065).

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38064

CVE-2026-38064 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_dial_call via the dialNumber parameter. This CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-38064) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-38064).

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38063

CVE-2026-38063 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_radio_on_with_ia_apn via the ia parameter. This CVE was published on [cvePublishedAt]2026-06-15T20:16:26.687Z[/cvePublishedAt] and modified on [cveModifiedAt]2026-06-15T21:05:18.653Z[/cveModifiedAt].

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38062

CVE-2026-38062 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_set_rat_mode via the ratMode parameter. This CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-38062) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-38062).

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38061

CVE-2026-38061 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_set_volume via the volume parameter. This CVE was published on [cvePublishedAt]2026-06-15T20:16:26.483Z[/cvePublishedAt] and modified on [cveModifiedAt]2026-06-15T21:05:18.653Z[/cveModifiedAt].

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38060

CVE-2026-38060 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_unlock_sim and is triggered via the pin parameter. This CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-38060) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-38060).

HIGH Tenda CVE published 2026-06-08

CVE-2026-11557

A high-severity vulnerability, CVE-2026-11557, has been identified in Tenda F451. The vulnerability affects the fromNatlimit function in the /goform/Natlimit file of the Web Management Interface. A remote attacker can exploit this vulnerability by manipulating the 'page' argument, leading to a stack-based buffer overflow. The CVSS score for this vulnerability is 7.4, indicating a high level of severity. T [truncated]

HIGH Tenda CVE published 2026-06-08

CVE-2026-11556

CVE-2026-11556 is a HIGH severity vulnerability with a CVSS score of 7.4. The vulnerability affects Tenda F451 versions 1.0.0.7 and 1.0.0.9, specifically in the formWriteFacMac function of the /goform/WriteFacMac file, allowing for os command injection via manipulation of the mac argument. This vulnerability can be exploited remotely.

HIGH Tenda CVE published 2026-06-08

CVE-2026-11553

CVE-2026-11553 is a HIGH severity vulnerability (CVSS Score: 7.4) affecting Tenda HG7HG9 and HG10 300001138_en_xpon devices. The vulnerability is caused by a stack-based buffer overflow in the `formPPPEdit` function of the `/boaform/formPPPEdit` file, which can be exploited remotely by manipulating the `encodename` argument. The exploit has been made public and could be used.

HIGH Tenda CVE published 2026-06-08

CVE-2026-11528

A high-severity vulnerability, CVE-2026-11528, was found in Tenda AC18 15.03.05.05. The vulnerability affects the function sub_45304 of the file /goform/getRebootStatus in the Web Management Interface. An attacker can exploit this vulnerability remotely, resulting in a stack-based buffer overflow. The CVSS score for this vulnerability is 7.4, indicating a high level of severity. The vulnerability was publ [truncated]

HIGH Tenda CVE published 2026-06-08

CVE-2026-11524

A vulnerability has been found in Tenda W20E 15.11.0.6. The function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface is impacted. The manipulation of the argument wifiFilterListRemark leads to a stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

HIGH Tenda CVE published 2026-06-08

CVE-2026-11523

A stack-based buffer overflow vulnerability has been discovered in Tenda W20E version 15.11.0.6. The issue affects the `formPortalAuth` function located in the `/goform/PortalAuth` file of the Web Management Interface. An attacker can exploit this vulnerability remotely by manipulating the `gotoUrl` argument, leading to a potential stack-based buffer overflow. The Common Vulnerability Scoring System (CVSS [truncated]

HIGH Tenda CVE published 2026-06-08

CVE-2026-11522

A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

HIGH Tenda CVE published 2026-06-08

CVE-2026-11504

A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration Endpoint. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.

HIGH Tenda CVE published 2026-06-08

CVE-2026-11503

CVE-2026-11503 is a HIGH severity vulnerability in Tenda CX12L 16.03.53.12. The Wi-Fi Configuration Endpoint is affected by a stack-based buffer overflow via ssid argument manipulation in the form_fast_setting_wifi_set function of /goform/fast_setting_wifi_set. Remote attackers can exploit this vulnerability. The exploit has been publicly disclosed.

HIGH Tenda CVE published 2026-06-08

CVE-2026-11498

A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely.

LOW Tenda CVE published 2026-06-08

CVE-2026-11493

A weakness was identified in Tenda AC15 15.03.05.19, specifically in an unknown function of the file /etc_ro/smb.conf of the Samba component. This issue allows for weak password requirements due to manipulation within the local network. The attack complexity is high and exploitability is difficult. The exploit has been made public and could be used for attacks. The CVSS score is 1.3, indicating a low severity.

HIGH Tenda CVE published 2026-05-31

CVE-2026-10191

A stack-based buffer overflow vulnerability exists in the Tenda W12 router firmware version 3.0.0.7(4763). The vulnerability is located in the `cgiWifiMacFilterSet` function within the `/bin/httpd` binary. An attacker can trigger the overflow by manipulating the `wifiMacFilterSet.macList.mac` argument through remote network access. The vulnerability has been publicly disclosed with available exploit mater [truncated]

MEDIUM Tenda CVE published 2026-05-31

CVE-2026-10190

A medium-severity denial-of-service vulnerability affects the Tenda W12 wireless access point firmware version 3.0.0.7(4763). The flaw resides in the cgiSysWebTimeoutSet function within the /bin/httpd binary of the device's Web Management Interface. Remote attackers with low privileges can trigger a denial of service by manipulating the web_over_time parameter. The vulnerability has been publicly disclose [truncated]

HIGH Tenda CVE published 2026-05-31

CVE-2026-10189

A stack-based buffer overflow vulnerability exists in the Tenda W12 router firmware version 3.0.0.7(4763). The vulnerability is located in the `cgiSysTimeInfoSet` function within the `/bin/httpd` binary. Remote attackers can trigger the overflow by manipulating the `sec` parameter. The exploit has been publicly disclosed, increasing the likelihood of active exploitation. The vendor attribution to Tenda is [truncated]

HIGH Tenda CVE published 2026-05-31

CVE-2026-10188

A stack-based buffer overflow vulnerability exists in the Tenda W12 wireless access point firmware version 3.0.0.7(4763). The flaw resides in the `cgistaKickOff` function within the `/bin/httpd` binary, where improper handling of the `staMac` parameter allows remote attackers to overflow the stack buffer. The vulnerability is remotely exploitable and public exploit material has been published, increasing [truncated]

HIGH Tenda CVE published 2026-05-25

CVE-2026-9431

A stack-based buffer overflow vulnerability exists in the Tenda F1202 router firmware version 1.2.0.20(408). The vulnerability is located in the `fromPptpUserAdd` function within the `/goform/PptpUserAdd` endpoint, where improper handling of the `opttype` parameter allows remote attackers to trigger memory corruption. The CVSS 4.0 vector indicates network attack vector with low attack complexity, low priv [truncated]

HIGH Tenda CVE published 2026-05-25

CVE-2026-9429

A stack-based buffer overflow vulnerability exists in the Tenda F1202 wireless router firmware version 1.2.0.20(408). The vulnerability is located in the `formWrlExtraSet` function within the `/goform/WrlExtraSet` endpoint, where improper handling of the `delno` parameter allows remote attackers to trigger memory corruption. The attack vector is network-accessible with low attack complexity and requires l [truncated]

HIGH Tenda CVE published 2026-05-25

CVE-2026-9428

A stack-based buffer overflow vulnerability exists in the Tenda F1202 router firmware version 1.2.0.20(408). The vulnerability is located in the `fromPPTPUserSetting` function within the `/goform/PPTPUserSetting` endpoint. Remote attackers can exploit this by manipulating the `delno` argument to trigger memory corruption. The CVSS 4.0 score of 7.4 (HIGH) reflects network attack vector, low attack complexi [truncated]

HIGH Tenda CVE published 2026-05-24

CVE-2026-9389

A buffer overflow vulnerability in the Tenda F456 router firmware version 1.0.0.5 allows remote attackers to execute arbitrary code via the `page` parameter in the `/goform/L7Im` endpoint's `frmL7ImForm` function. The vulnerability has a CVSS 4.0 score of 7.4 (HIGH severity) and public exploit disclosure increases immediate risk. The affected product is a consumer-grade wireless router, and successful exp [truncated]

LOW Tenda CVE published 2026-05-11

CVE-2026-8265

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. This vulnerability has been publicly disclosed and may be used by attackers. The CVE record and NVD entry provide additi [truncated]

LOW Tenda CVE published 2026-05-11

CVE-2026-8264

A low-severity vulnerability has been identified in Tenda AC6 15.03.06.23. The function formWifiApScan of the file /goform/WifiApScan in the httpd component is affected, allowing remote os command injection through manipulation of the wl2g.public.country/wl5g.public.country argument. The vulnerability has a CVSS score of 2.1 and is considered low severity. This type of vulnerability could allow an attacke [truncated]

LOW Tenda CVE published 2026-05-11

CVE-2026-8263

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01, specifically in the function fromSetWirelessRepeat of the file /goform/WifiExtraSet within the httpd component. The vulnerability allows for OS command injection through manipulation of the mac and ssid arguments. This issue can be exploited remotely, potentially leading to unauthorized command execution on affected systems. Users o [truncated]

LOW Tenda CVE published 2026-05-11

CVE-2026-8259

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vulnerability is caused by improper handling of the lan.ip argument [truncated]

HIGH Tenda CVE published 2026-05-08

CVE-2026-8138

CVE-2026-8138 is a high-severity vulnerability in Tenda CX12L firmware 16.03.53.12. The issue is a remote stack-based buffer overflow in PPTP server configuration handling, and the public disclosure notes that exploit code has been made available.

HIGH Tenda CVE published 2026-04-09

CVE-2026-5830

A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. This vulnerability has a high CVSS score of 7.4, indicating high severity. Users of Tenda AC15 15.03.05.18 should assess the vulnerability and ap [truncated]