Tenda
Tenda W20e Firmware: vulnerabilidades y CVE
Tenda W20e Firmware tiene 23 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 16 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses9
Críticas16
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-24112 | Crítica (9.8) | 0.55% | — | 2 mar 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addWewifiWhiteUser` function and processed by… |
| CVE-2026-24110 | Crítica (9.8) | 0.43% | — | 2 mar 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule` function and are processed by `ret = sscanf(pRule, "… |
| CVE-2026-24115 | Crítica (9.8) | 0.71% | — | 2 mar 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before concatenating them into `gstruleQos` may lead to buffer overflow. |
| CVE-2026-24114 | Crítica (9.8) | 0.64% | — | 2 mar 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`. |
| CVE-2026-24113 | Crítica (9.8) | 0.66% | — | 2 mar 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using… |
| CVE-2026-24111 | Crítica (9.8) | 0.66% | — | 2 mar 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addAuthUser` function and processed by `sscanf`… |
| CVE-2026-24109 | Crítica (9.8) | 0.66% | — | 2 mar 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this value is used in `sprintf` without validating variable sizes, it could… |
| CVE-2026-24108 | Crítica (9.8) | 0.66% | — | 2 mar 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using… |
| CVE-2026-24107 | Crítica (9.8) | 2.2% | — | 2 mar 2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities. |
| CVE-2025-44867 | Media (6.3) | 1.2% | — | 1 may 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a… |
| CVE-2025-44866 | Media (6.3) | 1.2% | — | 1 may 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted… |
| CVE-2025-44865 | Media (6.3) | 1.2% | — | 1 may 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted… |
| CVE-2025-44864 | Media (6.3) | 1.2% | — | 1 may 2025 | Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted… |
| CVE-2024-3874 | Alta (8.8) | 1.3% | — | 16 abr 2024 | A vulnerability was found in Tenda W20E 15.11.0.6. It has been declared as critical. This vulnerability affects the function formSetRemoteWebManage of the file /goform/SetRemoteWebManage. The manipulation of the… |
| CVE-2023-26806 | Crítica (9.8) | 0.93% | — | 19 mar 2023 | Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime, |
| CVE-2023-26805 | Crítica (9.8) | 0.93% | — | 19 mar 2023 | Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify. |
| CVE-2022-48130 | Crítica (9.8) | 0.93% | — | 2 feb 2023 | Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN. |
| CVE-2022-45997 | Alta (7.2) | 0.91% | — | 12 dic 2022 | Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow. |
| CVE-2022-45996 | Alta (7.2) | 2.3% | — | 12 dic 2022 | Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output. |
| CVE-2022-40868 | Crítica (9.8) | 1.1% | — | 23 sept 2022 | Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/ |
| CVE-2022-40867 | Crítica (9.8) | 1.1% | — | 23 sept 2022 | Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/ |
| CVE-2022-40866 | Crítica (9.8) | 1.1% | — | 23 sept 2022 | Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/ |
| CVE-2022-40855 | Crítica (9.8) | 14% | — | 23 sept 2022 | Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.