These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A high-severity vulnerability, CVE-2026-11528, was found in Tenda AC18 15.03.05.05. The vulnerability affects the function sub_45304 of the file /goform/getRebootStatus in the Web Management Interface. An attacker can exploit this vulnerability remotely, resulting in a stack-based buffer overflow. The CVSS score for this vulnerability is 7.4, indicating a high level of severity. The vulnerability was publ [truncated]
A vulnerability has been found in Tenda W20E 15.11.0.6. The function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface is impacted. The manipulation of the argument wifiFilterListRemark leads to a stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
A stack-based buffer overflow vulnerability has been discovered in Tenda W20E version 15.11.0.6. The issue affects the `formPortalAuth` function located in the `/goform/PortalAuth` file of the Web Management Interface. An attacker can exploit this vulnerability remotely by manipulating the `gotoUrl` argument, leading to a potential stack-based buffer overflow. The Common Vulnerability Scoring System (CVSS [truncated]
A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.
A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration Endpoint. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
CVE-2026-11503 is a HIGH severity vulnerability in Tenda CX12L 16.03.53.12. The Wi-Fi Configuration Endpoint is affected by a stack-based buffer overflow via ssid argument manipulation in the form_fast_setting_wifi_set function of /goform/fast_setting_wifi_set. Remote attackers can exploit this vulnerability. The exploit has been publicly disclosed.
A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack is possible to be carried out remotely.
A weakness was identified in Tenda AC15 15.03.05.19, specifically in an unknown function of the file /etc_ro/smb.conf of the Samba component. This issue allows for weak password requirements due to manipulation within the local network. The attack complexity is high and exploitability is difficult. The exploit has been made public and could be used for attacks. The CVSS score is 1.3, indicating a low severity.
A stack-based buffer overflow vulnerability exists in the Tenda W12 router firmware version 3.0.0.7(4763). The vulnerability is located in the `cgiWifiMacFilterSet` function within the `/bin/httpd` binary. An attacker can trigger the overflow by manipulating the `wifiMacFilterSet.macList.mac` argument through remote network access. The vulnerability has been publicly disclosed with available exploit mater [truncated]
A medium-severity denial-of-service vulnerability affects the Tenda W12 wireless access point firmware version 3.0.0.7(4763). The flaw resides in the cgiSysWebTimeoutSet function within the /bin/httpd binary of the device's Web Management Interface. Remote attackers with low privileges can trigger a denial of service by manipulating the web_over_time parameter. The vulnerability has been publicly disclose [truncated]
A stack-based buffer overflow vulnerability exists in the Tenda W12 router firmware version 3.0.0.7(4763). The vulnerability is located in the `cgiSysTimeInfoSet` function within the `/bin/httpd` binary. Remote attackers can trigger the overflow by manipulating the `sec` parameter. The exploit has been publicly disclosed, increasing the likelihood of active exploitation. The vendor attribution to Tenda is [truncated]
A stack-based buffer overflow vulnerability exists in the Tenda W12 wireless access point firmware version 3.0.0.7(4763). The flaw resides in the `cgistaKickOff` function within the `/bin/httpd` binary, where improper handling of the `staMac` parameter allows remote attackers to overflow the stack buffer. The vulnerability is remotely exploitable and public exploit material has been published, increasing [truncated]
A stack-based buffer overflow vulnerability exists in the Tenda F1202 router firmware version 1.2.0.20(408). The vulnerability is located in the `fromPptpUserAdd` function within the `/goform/PptpUserAdd` endpoint, where improper handling of the `opttype` parameter allows remote attackers to trigger memory corruption. The CVSS 4.0 vector indicates network attack vector with low attack complexity, low priv [truncated]
A stack-based buffer overflow vulnerability exists in the Tenda F1202 wireless router firmware version 1.2.0.20(408). The vulnerability is located in the `formWrlExtraSet` function within the `/goform/WrlExtraSet` endpoint, where improper handling of the `delno` parameter allows remote attackers to trigger memory corruption. The attack vector is network-accessible with low attack complexity and requires l [truncated]
A stack-based buffer overflow vulnerability exists in the Tenda F1202 router firmware version 1.2.0.20(408). The vulnerability is located in the `fromPPTPUserSetting` function within the `/goform/PPTPUserSetting` endpoint. Remote attackers can exploit this by manipulating the `delno` argument to trigger memory corruption. The CVSS 4.0 score of 7.4 (HIGH) reflects network attack vector, low attack complexi [truncated]
A buffer overflow vulnerability in the Tenda F456 router firmware version 1.0.0.5 allows remote attackers to execute arbitrary code via the `page` parameter in the `/goform/L7Im` endpoint's `frmL7ImForm` function. The vulnerability has a CVSS 4.0 score of 7.4 (HIGH severity) and public exploit disclosure increases immediate risk. The affected product is a consumer-grade wireless router, and successful exp [truncated]
A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. This vulnerability has been publicly disclosed and may be used by attackers. The CVE record and NVD entry provide additi [truncated]
A low-severity vulnerability has been identified in Tenda AC6 15.03.06.23. The function formWifiApScan of the file /goform/WifiApScan in the httpd component is affected, allowing remote os command injection through manipulation of the wl2g.public.country/wl5g.public.country argument. The vulnerability has a CVSS score of 2.1 and is considered low severity. This type of vulnerability could allow an attacke [truncated]
A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01, specifically in the function fromSetWirelessRepeat of the file /goform/WifiExtraSet within the httpd component. The vulnerability allows for OS command injection through manipulation of the mac and ssid arguments. This issue can be exploited remotely, potentially leading to unauthorized command execution on affected systems. Users o [truncated]
A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vulnerability is caused by improper handling of the lan.ip argument [truncated]
CVE-2026-8138 is a high-severity vulnerability in Tenda CX12L firmware 16.03.53.12. The issue is a remote stack-based buffer overflow in PPTP server configuration handling, and the public disclosure notes that exploit code has been made available.
A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. This vulnerability has a high CVSS score of 7.4, indicating high severity. Users of Tenda AC15 15.03.05.18 should assess the vulnerability and ap [truncated]
CVE-2025-52221 is a critical Buffer Overflow vulnerability in the formSetCfm function of Tenda AC6 15.03.05.16_multi, exploitable via the funcname, funcpara1, and funcpara2 parameters. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. This vulnerability allows an attacker to execute arbitrary code remotely, posing a significant risk to confidentiality, integrity, and availability. N [truncated]
A stack-based buffer overflow vulnerability has been identified in Tenda CX12L 16.03.53.12. The issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. This manipulation of the argument page causes a stack-based buffer overflow. The attack may be initiated remotely. Network administrators and security teams should prioritize patching this vulnerability to prevent potential re [truncated]
CVE-2026-5686 is a stack-based buffer overflow vulnerability in Tenda CX12L 16.03.53.12. The vulnerability affects the fromRouteStatic function in /goform/RouteStatic. The manipulation of the argument page results in a stack-based buffer overflow. The attack can be launched remotely. This vulnerability has a high CVSS score of 7.4, indicating a high severity level. Network administrators and security team [truncated]
CVE-2026-5685 is a HIGH severity vulnerability in Tenda CX12L 16.03.53.12. The fromAddressNat function in /goform/addressNat is susceptible to a stack-based buffer overflow via the page argument. Remote attackers can exploit this vulnerability. Evidence is based on CVE and NVD records. The vulnerability has a CVSS score of 7.4, indicating high severity. Network administrators and security teams managing T [truncated]
A stack-based buffer overflow vulnerability was determined in Tenda CX12L 16.03.53.12. The issue affects the fromwebExcptypemanFilter function of the file /goform/webExcptypemanFilter. This vulnerability can be exploited through manipulation of the argument page, requiring access to the local network. The CVSS score for this vulnerability is 7.3, classified as HIGH severity. Network administrators and sec [truncated]
A stack-based buffer overflow vulnerability was found in Tenda CX12L 16.03.53.12, affecting the fromP2pListFilter function of the /goform/P2pListFilter file. The vulnerability requires the attack to originate from the local network. The exploit has been made public and could be used. This vulnerability has a CVSS score of 2 and a CVSS severity of LOW. The attack vector is Adjacent (AV:A), and the attack c [truncated]
A flaw has been found in Tenda i12 1.0.0.11(3862), specifically in the formwrlSSIDset function of the /goform/wifiSSIDset file. This vulnerability, caused by manipulation of the index/wl_radio argument, leads to a stack-based buffer overflow and allows for remote exploitation. Network administrators and security teams should prioritize patching this vulnerability to prevent potential remote attacks. The C [truncated]
A stack-based buffer overflow vulnerability has been identified in Tenda CH22 1.0.0.1, specifically in the formWrlExtraSet function of the /goform/WrlExtraSet file. The vulnerability can be exploited remotely by manipulating the GO argument, potentially leading to significant damage if left unaddressed. Users of the affected product should apply vendor patches or mitigations as soon as possible. The explo [truncated]