📦 Ac15 Firmware

by Tenda

🔍 What is Ac15 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-63666

CRITICAL CVSS 9.8 Nov 12, 2025

The Tenda AC15 router firmware exposes password hashes in authentication cookies and uses weak session identifiers, allowing attackers to steal and replay cookies for unauthorized access. This affects...

CVE-2023-36103

CRITICAL CVSS 9.8 Sep 10, 2024

This CVE describes a command injection vulnerability in Tenda AC15 routers that allows remote attackers to execute arbitrary commands via crafted POST requests to the goform/SetIPTVCfg interface. Atta...

CVE-2023-30372

CRITICAL CVSS 9.8 Apr 24, 2023

This CVE describes a stack-based buffer overflow vulnerability in the 'xkjs_ver32' function of Tenda AC15 routers. Attackers can exploit this to execute arbitrary code with root privileges, potentiall...

CVE-2023-30375

CRITICAL CVSS 9.8 Apr 24, 2023

This CVE describes a stack-based buffer overflow vulnerability in the 'getIfIp' function of Tenda AC15 routers running firmware version V15.03.05.19. Attackers can exploit this to execute arbitrary co...

CVE-2023-30378

CRITICAL CVSS 9.8 Apr 24, 2023

A stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the affected function. This affects all use...

CVE-2023-30370

CRITICAL CVSS 9.8 Apr 24, 2023

CVE-2023-30370 is a critical stack-based buffer overflow vulnerability in Tenda AC15 routers' GetValue function. Attackers can exploit this to execute arbitrary code with root privileges, potentially ...

CVE-2022-28557

CRITICAL CVSS 9.8 May 4, 2022

This CVE describes a command injection vulnerability in Tenda AC15 routers that allows attackers to execute arbitrary commands on the device. When combined with CVE-2021-44971, it enables unconditiona...

CVE-2026-3400

HIGH CVSS 8.8 Mar 2, 2026

A stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the wpapsk_crypto2_4g parameter in the /goform/TextEditingConversion...

CVE-2025-11387

HIGH CVSS 8.8 Oct 7, 2025

A stack-based buffer overflow vulnerability exists in Tenda AC15 routers via the /goform/fast_setting_pppoe_set endpoint when manipulating the Password argument. This allows remote attackers to potent...

CVE-2025-11386

HIGH CVSS 8.8 Oct 7, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC15 routers via a stack-based buffer overflow in the SetDDNSCfg function. Attackers can exploit this without authenticati...

CVE-2025-10443

HIGH CVSS 8.8 Sep 15, 2025

A buffer overflow vulnerability in Tenda AC9 and AC15 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/exeCommand endpoint. This affects d...

CVE-2025-55564

HIGH CVSS 7.5 Aug 21, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC15 routers via a stack overflow in the fromSetIpMacBind function. Attackers can exploit this by sending specially crafte...

CVE-2025-5851

HIGH CVSS 8.8 Jun 9, 2025

A critical buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /goform/AdvSetLanip endpoint. Th...

CVE-2025-5849

HIGH CVSS 8.8 Jun 8, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /goform/SetRemoteWeb...

CVE-2025-0566

HIGH CVSS 8.8 Jan 19, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the 'mac' parameter in the formSetDevNetName function. This...

CVE-2024-10661

HIGH CVSS 8.8 Nov 1, 2024

This critical vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the DLNA configuration function. Attackers can exploit this wit...

CVE-2024-32303

HIGH CVSS 8.0 Apr 17, 2024

This CVE describes a stack overflow vulnerability in Tenda AC15 router firmware versions v15.03.20_multi, v15.03.05.19, and v15.03.05.18. The vulnerability exists in the fromWizardHandle function via ...

CVE-2024-30645

HIGH CVSS 8.0 Mar 29, 2024

This CVE describes a command injection vulnerability in Tenda AC15 routers where an attacker can execute arbitrary commands via the deviceName parameter. This allows remote code execution on affected ...

CVE-2024-2855

HIGH CVSS 8.8 Mar 24, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the 'time' parameter in the fromSetSysTime function. This a...

CVE-2024-2852

HIGH CVSS 8.8 Mar 24, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the 'urls' parameter in the saveParentControlInfo function....

CVE-2024-2850

HIGH CVSS 8.8 Mar 24, 2024

This CVE describes a critical stack-based buffer overflow vulnerability in Tenda AC15 routers. Attackers can remotely exploit this by manipulating the 'urls' parameter in the saveParentControlInfo fun...

CVE-2024-2815

HIGH CVSS 8.8 Mar 22, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the password parameter in the Cookie Handler. This affects ...

CVE-2024-2813

HIGH CVSS 8.8 Mar 22, 2024

This critical vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WiFi configuration function. Attackers can exploit this by ...

CVE-2024-2811

HIGH CVSS 8.8 Mar 22, 2024

This critical vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WPS configuration function. Attackers can exploit this to t...

CVE-2024-2809

HIGH CVSS 8.8 Mar 22, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the firewallEn parameter. This affects Tenda AC15 routers r...

CVE-2024-2807

HIGH CVSS 8.8 Mar 22, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the filePath parameter in the formExpandDlnaFile function. ...

CVE-2024-2805

HIGH CVSS 8.8 Mar 22, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the speed_dir parameter in the formSetSpeedWan function. Th...

CVE-2025-10442

MEDIUM CVSS 6.3 Sep 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on Tenda AC9 and AC15 routers through command injection in the formexeCommand function. Attackers can exploit ...

CVE-2025-8979

MEDIUM CVSS 6.6 Aug 14, 2025

This vulnerability in Tenda AC15 routers allows attackers to bypass firmware update authentication checks, potentially enabling malicious firmware installation. It affects users of Tenda AC15 routers ...

CVE-2025-25634

MEDIUM CVSS 6.5 Mar 5, 2025

A stack-based buffer overflow vulnerability exists in Tenda AC15 routers version 15.03.05.19. Attackers can exploit this by sending specially crafted requests to the GetParentControlInfo endpoint, pot...

CVE-2024-10280

MEDIUM CVSS 6.5 Oct 23, 2024

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...