📦 Ac9 Firmware
by Tenda
🔍 What is Ac9 Firmware?
Description coming soon...
🛡️ Security Overview
Click on a severity to filter vulnerabilities
⚠️ Known Vulnerabilities
This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC9 routers via the Telnet service. Attackers can gain full control of affected devices, potentially compromising netw...
This CVE describes a command injection vulnerability in Tenda AC9 routers that allows attackers to execute arbitrary commands via the deviceName parameter in the formsetUsbUnload function. Attackers c...
This CVE describes a stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code. The vulnerability affects Tenda AC9 v1.0 devices running firmware V15.03....
This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers by exploiting a stack overflow in the wanMTU parameter. Attackers can take full control of affected devices wi...
This vulnerability allows remote attackers to execute arbitrary code on Tenda AC9 routers by exploiting a stack overflow in the web interface. Attackers can take full control of affected devices witho...
This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC9 routers by injecting malicious commands into the SetSambaCfg form. Attackers can gain full control of affected dev...
This CVE describes a stack overflow vulnerability in Tenda AC9 v1.0 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/SetOnlineDevName...
This critical vulnerability allows remote attackers to execute arbitrary operating system commands with root privileges on Tenda AC9 routers. Attackers can exploit the command injection flaw in the ht...
A buffer overflow vulnerability in the setSchedWifi function of Tenda AC9 v.3.0 routers allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted data. ...
A buffer overflow vulnerability in Tenda router firmware allows remote attackers to execute arbitrary code via the formSetCfm function in the httpd service. This affects multiple Tenda router models i...
CVE-2023-41560 is a critical stack-based buffer overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/...
This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the PowerSaveSet function. Attackers can exploit this by sending specially crafte...
This CVE describes a critical stack overflow vulnerability in Tenda AC7 and AC9 routers that allows remote code execution. Attackers can exploit this by sending specially crafted requests to the vulne...
CVE-2023-41554 is a critical stack overflow vulnerability in Tenda AC9 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/WifiExtraSet ...
This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the SetIpMacBind function. Attackers can exploit this by sending specially crafte...
This CVE describes a stack overflow vulnerability in multiple Tenda router models via the speed_dir parameter in the formSetSpeedWan function. Attackers can exploit this to execute arbitrary code or c...
This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the addWifiMacFilter function. Attackers can exploit this by sending specially cr...
This vulnerability allows remote attackers to execute arbitrary code on affected Tenda routers via a stack overflow in the fromDhcpListClient function. Attackers can exploit this by sending specially ...
A stack overflow vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code via crafted HTTP requests to the goform/fast_setting_wifi_set endpoint. This affects Tenda AC9 rou...
A stack overflow vulnerability in the SetStaticRouteCfg() function of Tenda AC9 router's httpd service allows remote code execution. This affects Tenda AC9 router users running vulnerable firmware ver...
A buffer overflow vulnerability in Tenda AC9 and AC15 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/exeCommand endpoint. This affects d...
This critical vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the web management interface. Attackers can exploit this by send...
A critical buffer overflow vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code by sending specially crafted POST requests to the /goform/AdvSetLanip endpoint. This aff...
A stack-based buffer overflow vulnerability in Tenda AC9 routers allows remote attackers to execute arbitrary code via the fromSetIpMacBind function. This affects Tenda AC9 v3.0 routers running firmwa...
A stack-based buffer overflow vulnerability in Tenda AC9 v.3.0 routers allows remote attackers to execute arbitrary code via the formWifiBasicSet function. This affects users running firmware version ...
This vulnerability in Tenda AC9 routers allows remote attackers to access configuration files via the /cgi-bin/DownloadCfg.jpg endpoint, potentially exposing sensitive router settings and credentials....
This CVE describes an OS command injection vulnerability in Tenda AC9 routers where an attacker can execute arbitrary commands on the device by manipulating the usb.samba.guest.user parameter. The vul...
This vulnerability allows remote attackers to execute arbitrary operating system commands on Tenda AC9 and AC15 routers through command injection in the formexeCommand function. Attackers can exploit ...
This CSRF vulnerability in Tenda AC9 routers allows attackers to trick authenticated users into performing unauthorized actions like rebooting or restoring factory settings. It affects users of Tenda ...
A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...