PatchSiren

Tenda CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Tenda CVE published 2026-09-07

CVE-2026-86300

A flaw in Tenda AC9 15.03.05.14's Web Management component allows for improper authentication, which can be exploited remotely. The CVE record was published on 2026-09-07T12:17:21.520Z and has not been modified since then. The NVD entry is currently Received. This vulnerability impacts the function R7WebsSecurityHandler of the component Web Management, allowing for improper authentication. The attack may [truncated]

LOW Tenda CVE published 2026-09-05

CVE-2026-86150

CVE-2026-86150 is a security vulnerability detected in Tenda CP3 27.5.57.101, specifically in the custom-x/softap/hostapd file. The vulnerability is caused by manipulation of the wpa_passphrase argument, leading to hard-coded credentials. The attack can be launched remotely. This CVE record was published on 2026-09-05T23:17:41.337Z and has not been modified since then. Security teams should review the aff [truncated]

HIGH Tenda CVE published 2026-08-09

CVE-2026-19346

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T10:17:10.567Z and has not been modified since then. The vulnerability affects Tenda CH22 1.0.0.1, specifically the formCertListInfo function, allowing for command injection via the Name argument. The attack can be initiated remotely. Evidence is limited to public sources and may not reflect the f [truncated]

CRITICAL Tenda CVE published 2026-07-31

CVE-2026-67822

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T17:16:35.210Z and has not been modified since then. Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without le [truncated]

HIGH Tenda CVE published 2026-07-20

CVE-2026-16248

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01, affecting the function fromAdvSetLanip of the file /goform/AdvSetLanip in the httpd/netctrl component. The manipulation of the GetValue/SetValue arguments results in a stack-based buffer overflow. The attack may be performed remotely. This issue has a CVSS score of 7.4 and is classified as HIGH. Evidence is limited; verify affected scope and [truncated]

CRITICAL Tenda CVE published 2026-07-15

CVE-2026-51380

A Buffer Overflow vulnerability exists in Tenda AC10 v3 (firmware V03.03.16.09). The vulnerability is located in the /cgi-bin/UploadCfg endpoint and could allow attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code. The CVSS score for this vulnerability is 9.8, indicating a Critical severity level. This vulnerability can be exploited by attackers to disrupt the service [truncated]

HIGH Tenda CVE published 2026-07-13

CVE-2026-15543

A HIGH severity vulnerability was found in Tenda CH22 1.0.0.1, affecting the formCertListInfo function. The vulnerability is a buffer overflow caused by manipulation of the Name argument, allowing for remote attacks. The CVE record was published on 2026-07-13T08:16:20.967Z and has not been modified since then. The CVSS score is 7.4, and administrators and users of Tenda CH22 1.0.0.1 should be aware of thi [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51606

CVE-2026-51606 is a HIGH severity vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). The vulnerability causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across mul [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51605

CVE-2026-51605 is a stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991). An unauthenticated remote attacker can cause a denial of service via a crafted TEARDOWN request. This vulnerability has a high impact on network availability and requires immediate attention from users of the affected product.

HIGH Tenda CVE published 2026-07-09

CVE-2026-51604

CVE-2026-51604 is a stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). An unauthenticated remote attacker can cause a denial of service via a crafted PLAY request. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. This type of vulnerability can be used to disrupt service, and defenders should be cautious of potential impact on network ava [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51603

CVE-2026-51603 is a stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). An unauthenticated remote attacker can cause a denial of service via a crafted second SETUP request. To exploit this, the attacker must first complete OPTIONS, DESCRIBE, and a legitimate first SETUP request to obtain a valid session ID. The RTSP service's second-stage URL routing pars [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51602

A stack-based buffer overflow vulnerability exists in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). An unauthenticated remote attacker can cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the first SETUP request. This issue allows an attacker to supply a crafted URL that can trigger a stac [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51601

CVE-2026-51601 is a stack-based buffer overflow vulnerability in Tenda CP3 V3.0 firmware V31.1.9.91. The RTSP service fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker can send a PLAY request with an excessively long clock= value to cause the RTSP service to crash. This vulnerability has a high impact on affected s [truncated]

HIGH Tenda CVE published 2026-07-09

CVE-2026-51600

The Tenda CP3 V3.0 firmware V31.1.9.91 is vulnerable to a denial-of-service condition due to improper handling of RTSP requests. Specifically, the device does not validate the Content-Length header field in RTSP requests, including DESCRIBE, SETUP, and PLAY methods. When a request with a Content-Length header is received without a corresponding message body, the RTSP parser enters a persistent body-awaiti [truncated]

CRITICAL Tenda CVE published 2026-07-06

CVE-2026-11405

A hidden backdoor authentication mechanism was discovered in the web server binary /bin/httpd. This backdoor, located in the login() function, allows for admin-level access without proper authentication. The backdoor reads a password from the device configuration and compares it directly to the user-supplied password, granting admin access if they match.

HIGH Tenda CVE published 2026-06-29

CVE-2026-13519

A stack-based buffer overflow vulnerability was found in Tenda JD12L 16.03.53.23. The issue impacts the fromNatStaticSetting function of the /goform/NatStaticSetting file. The vulnerability can be exploited remotely by manipulating the page argument. The exploit has been made public and could potentially be used in attacks. Users of the affected product should apply patches or mitigations as soon as avail [truncated]

HIGH Tenda CVE published 2026-06-29

CVE-2026-13516

CVE-2026-13516 is a stack-based buffer overflow vulnerability detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in the vulnerability. The attack may be initiated remotely. The exploit is now public and may be used. This vulnerability has a CVSS score of 7.4 and a sev [truncated]

CRITICAL Tenda CVE published 2026-06-19

CVE-2026-51846

CVE-2026-51846 is a stack buffer overflow vulnerability in the Tenda AC7 router, specifically in the wanSpeed parameter of the /goform/AdvSetMacMtuWan route. This vulnerability, present in version 15.03.06.44, could allow for remote arbitrary code execution. The CVE was published on June 19, 2026. Given the potential for remote code execution, defenders should prioritize patching or mitigating this vulner [truncated]

CRITICAL Tenda CVE published 2026-06-19

CVE-2026-51845

CVE-2026-51845 is a stack buffer overflow vulnerability in Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the mac parameter. Defenders should assess exposure and prioritize patching due to potential remote exploitation. The CVE was published on 2026-06-19 and has not been assessed for CVSS score or severity. Limited information is available, emphasizing the n [truncated]

CRITICAL Tenda CVE published 2026-06-19

CVE-2026-51844

CVE-2026-51844 is a stack buffer overflow vulnerability in Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. This issue may allow attackers to execute arbitrary code. Affected users should review and apply patches from the vendor. The CVE was published on 2026-06-19 and has not been modified since then. The vulnerability's severity and s [truncated]

CRITICAL Tenda CVE published 2026-06-19

CVE-2026-51843

CVE-2026-51843 is a stack buffer overflow vulnerability in Tenda AC7 v15.03.06.44. The vulnerability exists in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. This issue may allow attackers to execute arbitrary code. Affected users should review and apply patches from the vendor. The CVE was published on 2026-06-19 and has not been modified since then. The vulnerability's severity and impa [truncated]

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38065

CVE-2026-38065 is a command injection vulnerability in Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_ims_on_with_apn via the ims_apn parameter. This CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-38065) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-38065).

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38064

CVE-2026-38064 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_dial_call via the dialNumber parameter. This CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-38064) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-38064).

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38063

CVE-2026-38063 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_radio_on_with_ia_apn via the ia parameter. This CVE was published on [cvePublishedAt]2026-06-15T20:16:26.687Z[/cvePublishedAt] and modified on [cveModifiedAt]2026-06-15T21:05:18.653Z[/cveModifiedAt].

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38062

CVE-2026-38062 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_set_rat_mode via the ratMode parameter. This CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-38062) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-38062).

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38061

CVE-2026-38061 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_set_volume via the volume parameter. This CVE was published on [cvePublishedAt]2026-06-15T20:16:26.483Z[/cvePublishedAt] and modified on [cveModifiedAt]2026-06-15T21:05:18.653Z[/cveModifiedAt].

CRITICAL Tenda CVE published 2026-06-15

CVE-2026-38060

CVE-2026-38060 is a command injection vulnerability in the Tenda 5G03 V05.03.02.04 (Version 1.0). The vulnerability exists in the function action_unlock_sim and is triggered via the pin parameter. This CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-38060) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-38060).

HIGH Tenda CVE published 2026-06-08

CVE-2026-11557

A high-severity vulnerability, CVE-2026-11557, has been identified in Tenda F451. The vulnerability affects the fromNatlimit function in the /goform/Natlimit file of the Web Management Interface. A remote attacker can exploit this vulnerability by manipulating the 'page' argument, leading to a stack-based buffer overflow. The CVSS score for this vulnerability is 7.4, indicating a high level of severity. T [truncated]

HIGH Tenda CVE published 2026-06-08

CVE-2026-11556

CVE-2026-11556 is a HIGH severity vulnerability with a CVSS score of 7.4. The vulnerability affects Tenda F451 versions 1.0.0.7 and 1.0.0.9, specifically in the formWriteFacMac function of the /goform/WriteFacMac file, allowing for os command injection via manipulation of the mac argument. This vulnerability can be exploited remotely.

HIGH Tenda CVE published 2026-06-08

CVE-2026-11553

CVE-2026-11553 is a HIGH severity vulnerability (CVSS Score: 7.4) affecting Tenda HG7HG9 and HG10 300001138_en_xpon devices. The vulnerability is caused by a stack-based buffer overflow in the `formPPPEdit` function of the `/boaform/formPPPEdit` file, which can be exploited remotely by manipulating the `encodename` argument. The exploit has been made public and could be used.