Tenda
Tenda Ax1806 Firmware: vulnerabilidades y CVE
Tenda Ax1806 Firmware tiene 61 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 20 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE61
Últimos 12 meses11
Críticas20
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-70644 | Alta (7.5) | 0.36% | — | 21 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-70650 | Alta (7.5) | 0.36% | — | 21 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetMacFilterCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-70645 | Alta (7.5) | 0.36% | — | 21 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilterCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-71020 | Alta (7.5) | 0.36% | — | 16 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-70746 | Alta (7.5) | 0.45% | — | 16 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-70656 | Alta (7.5) | 0.36% | — | 15 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-71019 | Alta (7.5) | 0.36% | — | 15 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-70744 | Alta (7.5) | 0.36% | — | 15 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-71021 | Alta (7.5) | 0.45% | — | 14 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-70747 | Alta (7.5) | 0.55% | — | 14 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serviceName parameter of the sub_65A28 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-70753 | Alta (7.5) | 0.45% | — | 13 ene 2026 | Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_4CA50 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2024-44557 | Crítica (9.8) | 0.61% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo. |
| CVE-2024-44555 | Crítica (9.8) | 0.73% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo. |
| CVE-2024-44553 | Crítica (9.8) | 0.63% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv. |
| CVE-2024-44552 | Crítica (9.8) | 0.38% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv. |
| CVE-2024-44551 | Crítica (9.8) | 0.63% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv. |
| CVE-2024-44550 | Crítica (9.8) | 0.63% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv. |
| CVE-2024-44549 | Crítica (9.8) | 0.38% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv. |
| CVE-2024-44558 | Crítica (9.8) | 0.63% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo. |
| CVE-2024-44556 | Crítica (9.8) | 0.38% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo. |
| CVE-2024-44565 | Crítica (9.8) | 0.61% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set. |
| CVE-2024-44563 | Crítica (9.8) | 0.61% | — | 26 ago 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo. |
| CVE-2024-41492 | Alta (7.5) | 0.59% | — | 19 jul 2024 | A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. |
| CVE-2024-40416 | Crítica (9.8) | 0.58% | — | 15 jul 2024 | A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow. |
| CVE-2024-40415 | Crítica (9.8) | 0.46% | — | 15 jul 2024 | A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow. |
| CVE-2024-40414 | Crítica (9.8) | 0.46% | — | 15 jul 2024 | A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow. |
| CVE-2024-40417 | Media (6.5) | 0.40% | — | 10 jul 2024 | A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow. |
| CVE-2024-35580 | Crítica (9.8) | 0.57% | — | 20 may 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv. |
| CVE-2024-35579 | Alta (7.7) | 0.42% | — | 20 may 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv. |
| CVE-2024-35578 | Alta (8) | 0.43% | — | 20 may 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.