Tenda
Tenda Ac500 Firmware: vulnerabilidades y CVE
Tenda Ac500 Firmware tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-7586 | Alta (7.4) | 1.2% | — | 14 jul 2025 | A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. Affected by this vulnerability is the function formSetAPCfg of the file /goform/setWtpData. The manipulation of the argument… |
| CVE-2024-10280 | Alta (7.1) | 0.80% | — | 23 oct 2024 | A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file… |
| CVE-2024-32320 | Media (5.9) | 0.58% | — | 17 abr 2024 | Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function. |
| CVE-2024-32318 | Crítica (9.8) | 0.78% | — | 17 abr 2024 | Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function. |
| CVE-2024-32316 | Media (6.5) | 0.40% | — | 17 abr 2024 | Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function. |
| CVE-2024-32314 | Baja (3.8) | 1.0% | — | 17 abr 2024 | Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter. |
| CVE-2023-46060 | Alta (7.5) | 0.81% | — | 17 abr 2024 | A Buffer Overflow vulnerability in Tenda AC500 v.2.0.1.9 allows a remote attacker to cause a denial of service via the port parameter at the goform/setVlanInfo component. |
| CVE-2024-3910 | Alta (8.8) | 1.7% | — | 17 abr 2024 | A vulnerability, which was classified as critical, has been found in Tenda AC500 2.0.1.9(1307). Affected by this issue is the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the… |
| CVE-2024-3909 | Crítica (9.8) | 1.7% | — | 17 abr 2024 | A vulnerability classified as critical was found in Tenda AC500 2.0.1.9(1307). Affected by this vulnerability is the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput… |
| CVE-2024-3908 | Crítica (9.8) | 8.7% | — | 17 abr 2024 | A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command… |
| CVE-2024-3907 | Crítica (9.8) | 1.9% | — | 17 abr 2024 | A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been rated as critical. This issue affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to… |
| CVE-2024-3906 | Alta (8.8) | 1.7% | — | 17 abr 2024 | A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument… |
| CVE-2024-3905 | Alta (8.8) | 1.8% | — | 17 abr 2024 | A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been classified as critical. This affects the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password… |
| CVE-2023-25235 | Alta (7.5) | 11% | — | 27 feb 2023 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid. |
| CVE-2023-25234 | Crítica (9.8) | 17% | — | 27 feb 2023 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface. |
| CVE-2023-25233 | Crítica (9.8) | 0.97% | — | 27 feb 2023 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.