Tendacn
Tendacn Ac10u Firmware: vulnerabilidades y CVE
Tendacn Ac10u Firmware tiene 23 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 23 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses0
Críticas23
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-0932 | Crítica (9.8) | 0.89% | — | 26 ene 2024 | A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This issue affects the function setSmartPowerManagement. The manipulation of the argument time leads to… |
| CVE-2024-0931 | Crítica (9.8) | 0.89% | — | 26 ene 2024 | A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. This vulnerability affects the function saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to… |
| CVE-2024-0930 | Crítica (9.8) | 15% | — | 26 ene 2024 | A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function fromSetWirelessRepeat. The manipulation of the argument wpapsk_crypto leads to stack-based buffer… |
| CVE-2024-0929 | Crítica (9.8) | 1.1% | — | 26 ene 2024 | A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Affected by this issue is the function fromNatStaticSetting. The manipulation of the argument page leads to stack-based… |
| CVE-2024-0928 | Crítica (9.8) | 1.1% | — | 26 ene 2024 | A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been declared as critical. Affected by this vulnerability is the function fromDhcpListClient. The manipulation of the argument page/listN leads to… |
| CVE-2024-0927 | Crítica (9.8) | 0.84% | — | 26 ene 2024 | A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been classified as critical. Affected is the function fromAddressNat. The manipulation of the argument entrys/mitInterface/page leads to… |
| CVE-2024-0926 | Crítica (9.8) | 0.91% | — | 26 ene 2024 | A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This issue affects the function formWifiWpsOOB. The manipulation of the argument index leads to stack-based buffer overflow.… |
| CVE-2024-0925 | Crítica (9.8) | 0.91% | — | 26 ene 2024 | A vulnerability has been found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This vulnerability affects the function formSetVirtualSer. The manipulation of the argument list leads to stack-based… |
| CVE-2024-0923 | Crítica (9.8) | 0.89% | — | 26 ene 2024 | A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of the argument devName leads to… |
| CVE-2024-0922 | Crítica (9.8) | 0.89% | — | 26 ene 2024 | A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this vulnerability is the function formQuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based… |
| CVE-2023-44023 | Crítica (9.8) | 1.1% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function. |
| CVE-2023-44022 | Crítica (9.8) | 1.1% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function. |
| CVE-2023-44021 | Crítica (9.8) | 1.1% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the formSetClientState function. |
| CVE-2023-44020 | Crítica (9.8) | 1.1% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function. |
| CVE-2023-44019 | Crítica (9.8) | 1.1% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the mac parameter in the GetParentControlInfo function. |
| CVE-2023-44018 | Crítica (9.8) | 16% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function. |
| CVE-2023-44017 | Crítica (9.8) | 1.1% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function. |
| CVE-2023-44016 | Crítica (9.8) | 1.1% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function. |
| CVE-2023-44015 | Crítica (9.8) | 0.79% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the setSchedWifi function. |
| CVE-2023-44014 | Crítica (9.8) | 1.1% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain multiple stack overflows in the formSetMacFilterCfg function via the macFilterType and deviceList parameters. |
| CVE-2023-44013 | Crítica (9.8) | 1.1% | — | 27 sept 2023 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the list parameter in the fromSetIpMacBind function. |
| CVE-2021-45401 | Crítica (9.8) | 2.5% | — | 18 feb 2022 | A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client… |
| CVE-2020-22079 | Crítica (9.8) | 4.2% | — | 29 oct 2021 | Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg. |