PatchSiren

Tenda CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Tenda CVE published 2026-04-05

CVE-2026-5567

A buffer overflow vulnerability has been identified in Tenda M3 1.0.0.10, specifically in the setAdvPolicyData function of the /goform/setAdvPolicyData component. This issue allows remote attackers to execute arbitrary code by manipulating the policyType argument. The vulnerability has a CVSS score of 7.4, indicating high severity. Evidence suggests that an exploit for this vulnerability has been publishe [truncated]

MEDIUM Tenda CVE published 2026-04-05

CVE-2026-5527

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. The issue affects some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of a hard-coded cryptographic key. It is possible to initiate the attack remotely. The vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. Users [truncated]

MEDIUM Tenda CVE published 2026-04-04

CVE-2026-5526

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The attack may be performed from remote. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Users of Tenda 4G03 Pro should be aware of this security flaw and ta [truncated]

HIGH Tenda CVE published 2026-03-31

CVE-2026-5204

A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack can be initiated remotely. The vulnerability has a high CVSS score of 7.4, indicating high severity. Users of Tenda CH22 1.0.0.1 should assess the v [truncated]

Known exploited Tenda CVE published 2021-11-03

CVE-2021-31755

CVE-2021-31755 is a Tenda AC11 Router stack buffer overflow vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03, with a remediation due date of 2021-11-17. The supplied authoritative sources identify the issue and the need to apply vendor-provided updates, but do not provide additional technical detail in this corpus.

Known exploited Tenda CVE published 2021-11-03

CVE-2020-10987

CVE-2020-10987 is a remote code execution vulnerability affecting the Tenda AC1900 Router AC15 Model. CISA lists it in the Known Exploited Vulnerabilities catalog, which means it is known to be exploited in the wild. For defenders, this makes the issue especially important for any environment using this router model, particularly if the device is internet-facing or difficult to monitor.

Known exploited Tenda CVE published 2021-11-03

CVE-2018-14558

CVE-2018-14558 is a command injection vulnerability affecting Tenda AC7, AC9, and AC10 routers. CISA lists the issue in its Known Exploited Vulnerabilities catalog, which means it has been identified as actively exploited or otherwise confirmed as a real-world attack risk. The supplied guidance is straightforward: apply updates per vendor instructions and treat affected devices as a security priority.