📦 Ac18 Firmware

by Tenda

🔍 What is Ac18 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-57579

CRITICAL CVSS 9.8 Jan 16, 2025

This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote code execution. Attackers can exploit the limitSpeedUp parameter in the formSetClientState function to execut...

CVE-2024-57581

CRITICAL CVSS 9.8 Jan 16, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers by exploiting a stack overflow in the firewall configuration function. Attackers can gain full control of aff...

CVE-2024-57583

CRITICAL CVSS 9.8 Jan 16, 2025

This CVE describes a command injection vulnerability in Tenda AC18 routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit this by sending specially crafted in...

CVE-2024-57575

CRITICAL CVSS 9.8 Jan 16, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers by exploiting a stack overflow in the WiFi configuration function. Attackers can gain full control of affecte...

CVE-2024-33835

CRITICAL CVSS 9.8 May 1, 2024

This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the vulnerable parameter. The vu...

CVE-2024-28537

CRITICAL CVSS 9.8 Mar 18, 2024

This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote attackers to execute arbitrary code or cause denial of service. The vulnerability exists in the fromNatStatic...

CVE-2024-28535

CRITICAL CVSS 9.8 Mar 12, 2024

CVE-2024-28535 is a critical stack overflow vulnerability in Tenda AC18 routers that allows remote code execution. Attackers can exploit the mitInterface parameter in the fromAddressNat function to cr...

CVE-2023-38823

CRITICAL CVSS 9.8 Nov 20, 2023

A buffer overflow vulnerability in Tenda router firmware allows remote attackers to execute arbitrary code via the formSetCfm function in the httpd service. This affects multiple Tenda router models i...

CVE-2023-30135

CRITICAL CVSS 9.8 May 5, 2023

This CVE describes a command injection vulnerability in Tenda AC18 routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit this by sending specially crafted re...

CVE-2022-30472

CRITICAL CVSS 9.8 May 26, 2022

This CVE describes a critical stack-based buffer overflow vulnerability in Tenda AC18 routers running firmware version 15.03.05.19(6318). Attackers can exploit this vulnerability to execute arbitrary ...

CVE-2022-30474

CRITICAL CVSS 9.8 May 26, 2022

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC Series routers via a heap overflow in the httpd module when processing /goform/saveParentControlInfo requests. Attacker...

CVE-2022-30476

CRITICAL CVSS 9.8 May 26, 2022

This critical vulnerability in Tenda AC Series routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the httpd module. Attackers can exploit this by sending sp...

CVE-2025-14993

HIGH CVSS 8.8 Dec 21, 2025

This CVE describes a remote stack-based buffer overflow vulnerability in Tenda AC18 routers. Attackers can exploit this by sending specially crafted HTTP requests to the vulnerable SetDlnaCfg endpoint...

CVE-2025-14992

HIGH CVSS 8.8 Dec 21, 2025

This CVE describes a stack-based buffer overflow vulnerability in Tenda AC18 routers running firmware version 15.03.05.05. Attackers can remotely exploit this vulnerability by sending specially crafte...

CVE-2025-63835

HIGH CVSS 8.8 Nov 10, 2025

A stack-based buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to crash the device or potentially execute arbitrary code by sending oversized data to the guestSsid parameter...

CVE-2025-11328

HIGH CVSS 8.8 Oct 6, 2025

This vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the DDNS configuration endpoint. Attackers can exploit this without auth...

CVE-2025-11326

HIGH CVSS 8.8 Oct 6, 2025

This CVE describes a stack-based buffer overflow vulnerability in Tenda AC18 routers through manipulation of the wifi_chkHz parameter in the WifiMacFilterSet endpoint. Attackers can exploit this remot...

CVE-2025-11324

HIGH CVSS 8.8 Oct 6, 2025

A stack-based buffer overflow vulnerability exists in Tenda AC18 routers via the /goform/setNotUpgrade endpoint. Attackers can remotely execute arbitrary code by manipulating the newVersion parameter....

CVE-2025-11325

HIGH CVSS 8.8 Oct 6, 2025

A stack-based buffer overflow vulnerability exists in Tenda AC18 routers via the /goform/fast_setting_pppoe_set endpoint. Attackers can remotely exploit this by manipulating the Username parameter to ...

CVE-2025-60663

HIGH CVSS 7.5 Oct 2, 2025

This CVE describes a stack overflow vulnerability in Tenda AC18 routers that allows remote attackers to execute arbitrary code or cause denial of service. Attackers can exploit this by sending special...

CVE-2025-60660

HIGH CVSS 7.5 Oct 2, 2025

A stack overflow vulnerability in Tenda AC18 routers allows attackers to execute arbitrary code by sending specially crafted requests to the vulnerable function. This affects Tenda AC18 router users r...

CVE-2025-60662

HIGH CVSS 7.5 Oct 2, 2025

A stack overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted requests to the wanSpeed parameter. This ...

CVE-2025-11122

HIGH CVSS 8.8 Sep 28, 2025

A stack-based buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/WizardHandle endpoint. This aff...

CVE-2025-11120

HIGH CVSS 8.8 Sep 28, 2025

A buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by exploiting the formSetServerConfig function. This affects Tenda AC8 routers running firmware v...

CVE-2025-9023

HIGH CVSS 8.8 Aug 15, 2025

A buffer overflow vulnerability in Tenda AC7 and AC18 routers allows remote attackers to execute arbitrary code by manipulating the Time parameter in the formSetSchedLed function. This affects routers...

CVE-2025-5608

HIGH CVSS 8.8 Jun 4, 2025

A critical buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by manipulating the rebootTime parameter. This affects Tenda AC18 routers running firmw...

CVE-2025-0528

HIGH CVSS 7.2 Jan 17, 2025

This critical vulnerability in Tenda AC8, AC10, and AC18 routers allows remote attackers to execute arbitrary commands via command injection in the HTTP request handler for the /goform/telnet endpoint...

CVE-2024-57578

HIGH CVSS 8.8 Jan 16, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers via a stack overflow in the formSetCfm function. Attackers can exploit this by sending specially crafted requ...

CVE-2024-41630

HIGH CVSS 7.6 Jul 31, 2024

A stack-based buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the ssid parameter. This affects Tenda AC18...

CVE-2024-33181

HIGH CVSS 8.8 Jul 16, 2024

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers via a stack-based buffer overflow in the addWifiMacFilter function. Attackers can exploit this by sending spe...

CVE-2024-34974

HIGH CVSS 8.2 May 14, 2024

A buffer overflow vulnerability in Tenda AC18 routers allows attackers to execute arbitrary code by sending specially crafted requests to the formSetPPTPServer function. This affects users running Ten...

CVE-2024-2489

HIGH CVSS 8.8 Mar 15, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by manipulating the 'list' argument in the formSetQosBand function. This af...

CVE-2024-2487

HIGH CVSS 8.8 Mar 15, 2024

This critical vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formSetDeviceName function. Attackers can exploit this by s...

CVE-2024-2485

HIGH CVSS 8.8 Mar 15, 2024

A critical stack-based buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary code by manipulating the speed_dir parameter in the formSetSpeedWan function. Th...

CVE-2025-60661

MEDIUM CVSS 5.3 Oct 2, 2025

A stack overflow vulnerability in Tenda AC18 routers allows attackers to execute arbitrary code or cause denial of service by sending specially crafted requests to the cloneType parameter. This affect...

CVE-2025-8182

MEDIUM CVSS 5.6 Jul 26, 2025

This vulnerability in Tenda AC18 routers allows attackers to exploit weak password requirements in the Samba configuration file. Attackers can potentially gain unauthorized access to SMB shares if the...

CVE-2025-5606

MEDIUM CVSS 6.3 Jun 4, 2025

This critical vulnerability in Tenda AC18 routers allows remote attackers to execute arbitrary commands via command injection in the formSetIptv function. Attackers can exploit this to take control of...

CVE-2024-10280

MEDIUM CVSS 6.5 Oct 23, 2024

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...