Tenda
Tenda A18 Firmware: vulnerabilidades y CVE
Tenda A18 Firmware tiene 11 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2930 | Baja (2.1) | 0.59% | — | 22 feb 2026 | A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. Such manipulation of the argument boundary… |
| CVE-2026-2877 | Alta (7.4) | 0.96% | — | 21 feb 2026 | A vulnerability has been found in Tenda A18 15.13.07.13. This affects the function strcpy of the file /goform/WifiExtraSet of the component Httpd Service. The manipulation of the argument wpapsk_crypto5g leads to… |
| CVE-2026-2876 | Alta (7.4) | 0.96% | — | 21 feb 2026 | A vulnerability was determined in Tenda A18 15.13.07.13. This affects the function parse_macfilter_rule of the file /goform/setBlackRule. This manipulation of the argument deviceList causes stack-based buffer overflow.… |
| CVE-2025-0848 | Alta (7.1) | 1.2% | — | 30 ene 2025 | A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The… |
| CVE-2024-32305 | Alta (8.8) | 0.61% | — | 17 abr 2024 | Tenda A18 v15.03.05.05 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function. |
| CVE-2023-50585 | Crítica (9.8) | 0.70% | — | 9 ene 2024 | Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function. |
| CVE-2023-39829 | Alta (7.5) | 0.81% | — | 14 ago 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function. |
| CVE-2023-39828 | Alta (7.5) | 0.81% | — | 14 ago 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function. |
| CVE-2023-39827 | Alta (7.5) | 0.81% | — | 14 ago 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function. |
| CVE-2022-44932 | Alta (7.5) | 0.68% | — | 8 dic 2022 | An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service. |
| CVE-2022-44931 | Alta (7.5) | 0.88% | — | 8 dic 2022 | Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.