Tenda
Tenda Ax12 Firmware: vulnerabilidades y CVE
Tenda Ax12 Firmware tiene 31 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses0
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-29215 | Media (6.5) | 0.82% | — | 20 mar 2025 | Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList. |
| CVE-2025-29214 | Alta (7.5) | 0.56% | — | 20 mar 2025 | Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg. |
| CVE-2024-39963 | Alta (8) | 1.5% | — | 19 jul 2024 | AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via… |
| CVE-2024-40503 | Media (6.5) | 0.40% | — | 16 jul 2024 | An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packet handling. |
| CVE-2024-40412 | Media (6.8) | 0.34% | — | 10 jul 2024 | Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function. |
| CVE-2024-28383 | Crítica (9.8) | 0.82% | — | 14 mar 2024 | Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function. |
| CVE-2023-47422 | Alta (8.8) | 0.49% | — | 20 feb 2024 | An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via… |
| CVE-2023-49427 | Alta (7.5) | 0.62% | — | 10 ene 2024 | Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function. |
| CVE-2023-49437 | Crítica (9.8) | 2.4% | — | 7 dic 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. |
| CVE-2023-49428 | Crítica (9.8) | 2.5% | — | 7 dic 2023 | Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. |
| CVE-2023-49426 | Crítica (9.8) | 0.92% | — | 7 dic 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg. |
| CVE-2023-49425 | Crítica (9.8) | 0.92% | — | 7 dic 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg . |
| CVE-2023-49424 | Crítica (9.8) | 0.92% | — | 7 dic 2023 | Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg. |
| CVE-2022-45995 | Crítica (9.8) | 1.1% | — | 5 ene 2023 | There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not to restart or even execute arbitrary code. It is a different vulnerability from… |
| CVE-2022-45980 | Alta (8.8) | 7.5% | — | 12 dic 2022 | Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet . |
| CVE-2022-45979 | Alta (7.5) | 0.82% | — | 12 dic 2022 | Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set . |
| CVE-2022-45977 | Alta (8.8) | 2.1% | — | 12 dic 2022 | Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function. |
| CVE-2022-45043 | Alta (8.8) | 2.2% | — | 12 dic 2022 | Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set. |
| CVE-2022-37292 | Media (5.5) | 0.30% | — | 25 ago 2022 | Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, which satisfies the request of the upper-level interface function sub_430124, that is, handles the post… |
| CVE-2022-28917 | Alta (7.5) | 9.6% | — | 18 may 2022 | Tenda AX12 v22.03.01.21_cn was discovered to contain a stack overflow via the lanIp parameter in /goform/AdvSetLanIp. |
| CVE-2022-28082 | Crítica (9.8) | 8.9% | — | 4 may 2022 | Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList. |
| CVE-2022-28561 | Crítica (9.8) | 10% | — | 3 may 2022 | There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload |
| CVE-2022-27375 | Media (6.5) | 0.46% | — | 25 abr 2022 | Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet. |
| CVE-2022-27374 | Media (6.5) | 0.46% | — | 25 abr 2022 | Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot. |
| CVE-2022-25561 | Alta (7.5) | 1.2% | — | 10 mar 2022 | Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42DE00. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter. |
| CVE-2022-25560 | Alta (7.5) | 1.2% | — | 10 mar 2022 | Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_4327CC. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter. |
| CVE-2022-25556 | Alta (7.5) | 1.2% | — | 10 mar 2022 | Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub_42E328. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter. |
| CVE-2021-46408 | Alta (7.5) | 1.2% | — | 10 mar 2022 | Tenda AX12 v22.03.01.21 was discovered to contain a stack buffer overflow in the function sub_422CE4. This vulnerability allows attackers to cause a Denial of Service (DoS) via the strcpy parameter. |
| CVE-2021-45391 | Alta (7.5) | 1.8% | — | 16 feb 2022 | A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/setIPv6Status binary file /usr/sbin/httpd via the conType parameter, which causes a Denial of Service. |
| CVE-2021-45392 | Alta (7.5) | 12% | — | 14 feb 2022 | A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.