📦 Ac9 Firmware

by Tenda

🔍 What is Ac9 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-45042

CRITICAL CVSS 9.8 May 5, 2025

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC9 routers via the Telnet service. Attackers can gain full control of affected devices, potentially compromising netw...

CVE-2025-44872

CRITICAL CVSS 9.8 May 2, 2025

This CVE describes a command injection vulnerability in Tenda AC9 routers that allows attackers to execute arbitrary commands via the deviceName parameter in the formsetUsbUnload function. Attackers c...

CVE-2025-45427

CRITICAL CVSS 9.8 Apr 23, 2025

This CVE describes a stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code. The vulnerability affects Tenda AC9 v1.0 devices running firmware V15.03....

CVE-2025-29384

CRITICAL CVSS 9.8 Mar 14, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers by exploiting a stack overflow in the wanMTU parameter. Attackers can take full control of affected devices wi...

CVE-2025-29386

CRITICAL CVSS 9.8 Mar 14, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers by exploiting a stack overflow in the web interface. Attackers can take full control of affected devices witho...

CVE-2025-22949

CRITICAL CVSS 9.8 Jan 10, 2025

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC9 routers by injecting malicious commands into the SetSambaCfg form. Attackers can gain full control of affected dev...

CVE-2025-22946

CRITICAL CVSS 9.8 Jan 10, 2025

This CVE describes a stack overflow vulnerability in Tenda AC9 v1.0 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/SetOnlineDevName...

CVE-2024-42634

CRITICAL CVSS 9.8 Aug 16, 2024

This critical vulnerability allows remote attackers to execute arbitrary operating system commands with root privileges on Tenda AC9 routers. Attackers can exploit the command injection flaw in the ht...

CVE-2024-24543

CRITICAL CVSS 9.8 Feb 5, 2024

A buffer overflow vulnerability in the setSchedWifi function of Tenda AC9 v.3.0 routers allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted data. ...

CVE-2023-38823

CRITICAL CVSS 9.8 Nov 20, 2023

A buffer overflow vulnerability in Tenda router firmware allows remote attackers to execute arbitrary code via the formSetCfm function in the httpd service. This affects multiple Tenda router models i...

CVE-2023-41560

CRITICAL CVSS 9.8 Aug 30, 2023

CVE-2023-41560 is a critical stack-based buffer overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/...

CVE-2023-41562

CRITICAL CVSS 9.8 Aug 30, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the PowerSaveSet function. Attackers can exploit this by sending specially crafte...

CVE-2023-41552

CRITICAL CVSS 9.8 Aug 30, 2023

This CVE describes a critical stack overflow vulnerability in Tenda AC7 and AC9 routers that allows remote code execution. Attackers can exploit this by sending specially crafted requests to the vulne...

CVE-2023-41554

CRITICAL CVSS 9.8 Aug 30, 2023

CVE-2023-41554 is a critical stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/WifiExtraSet ...

CVE-2023-41556

CRITICAL CVSS 9.8 Aug 30, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the SetIpMacBind function. Attackers can exploit this by sending specially crafte...

CVE-2023-38936

CRITICAL CVSS 9.8 Aug 7, 2023

This CVE describes a stack overflow vulnerability in multiple Tenda router models via the speed_dir parameter in the formSetSpeedWan function. Attackers can exploit this to execute arbitrary code or c...

CVE-2023-38930

CRITICAL CVSS 9.8 Aug 7, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the addWifiMacFilter function. Attackers can exploit this by sending specially cr...

CVE-2023-37717

CRITICAL CVSS 9.8 Jul 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the fromDhcpListClient function. Attackers can exploit this by sending specially ...

CVE-2022-28560

CRITICAL CVSS 9.8 May 3, 2022

A stack overflow vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code via crafted HTTP requests to the goform/fast_setting_wifi_set endpoint. This affects Tenda AC9 rou...

CVE-2022-27016

CRITICAL CVSS 9.8 Apr 7, 2022

A stack overflow vulnerability in the SetStaticRouteCfg() function of Tenda AC9 router's httpd service allows remote code execution. This affects Tenda AC9 router users running vulnerable firmware ver...

CVE-2025-10443

HIGH CVSS 8.8 Sep 15, 2025

A buffer overflow vulnerability in Tenda AC9 and AC15 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/exeCommand endpoint. This affects d...

CVE-2025-5847

HIGH CVSS 8.8 Jun 8, 2025

This critical vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the web management interface. Attackers can exploit this by send...

CVE-2025-5839

HIGH CVSS 8.8 Jun 7, 2025

A critical buffer overflow vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code by sending specially crafted POST requests to the /goform/AdvSetLanip endpoint. This aff...

CVE-2024-25748

HIGH CVSS 8.8 Feb 22, 2024

A stack-based buffer overflow vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code via the fromSetIpMacBind function. This affects Tenda AC9 v3.0 routers running firmwa...

CVE-2024-25756

HIGH CVSS 8.0 Feb 22, 2024

A stack-based buffer overflow vulnerability in Tenda AC9 v.3.0 routers allows remote attackers to execute arbitrary code via the formWifiBasicSet function. This affects users running firmware version ...

CVE-2025-14286

MEDIUM CVSS 5.3 Dec 9, 2025

This vulnerability in Tenda AC9 routers allows remote attackers to access configuration files via the /cgi-bin/DownloadCfg.jpg endpoint, potentially exposing sensitive router settings and credentials....

CVE-2025-57639

MEDIUM CVSS 6.5 Sep 23, 2025

This CVE describes an OS command injection vulnerability in Tenda AC9 routers where an attacker can execute arbitrary commands on the device by manipulating the usb.samba.guest.user parameter. The vul...

CVE-2025-10442

MEDIUM CVSS 6.3 Sep 15, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on Tenda AC9 and AC15 routers through command injection in the formexeCommand function. Attackers can exploit ...

CVE-2025-5900

MEDIUM CVSS 4.3 Jun 9, 2025

This CSRF vulnerability in Tenda AC9 routers allows attackers to trick authenticated users into performing unauthorized actions like rebooting or restoring factory settings. It affects users of Tenda ...

CVE-2024-10280

MEDIUM CVSS 6.5 Oct 23, 2024

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...