📦 W9 Firmware

by Tenda

🔍 What is W9 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-51098

CRITICAL CVSS 9.8 Dec 26, 2023

This CVE describes a command injection vulnerability in Tenda W9 routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit this vulnerability by sending speciall...

CVE-2023-51100

CRITICAL CVSS 9.8 Dec 26, 2023

This CVE describes a command injection vulnerability in Tenda W9 routers that allows attackers to execute arbitrary commands on the device. The vulnerability exists in the formGetDiagnoseInfo function...

CVE-2023-51102

CRITICAL CVSS 9.8 Dec 26, 2023

CVE-2023-51102 is a critical stack overflow vulnerability in Tenda W9 routers that allows remote attackers to execute arbitrary code or cause denial of service. The vulnerability exists in the formWif...

CVE-2024-52788

HIGH CVSS 8.0 Nov 19, 2024

Tenda W9 routers version 1.0.0.7(4456) contain a hardcoded root password in the /etc_ro/shadow file, allowing attackers to gain administrative access. This affects all users of this specific router mo...

CVE-2024-4243

HIGH CVSS 8.8 Apr 26, 2024

A critical stack-based buffer overflow vulnerability in Tenda W9 routers allows remote attackers to execute arbitrary code by manipulating the ssidIndex parameter. This affects Tenda W9 router users r...

CVE-2024-4241

HIGH CVSS 8.8 Apr 26, 2024

This critical vulnerability in Tenda W9 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formQosManageDouble_auto function. Attackers can exploit this...

CVE-2024-0541

HIGH CVSS 8.8 Jan 15, 2024

A critical stack-based buffer overflow vulnerability exists in Tenda W9 routers running firmware version 1.0.0.7(4456). Attackers can remotely exploit this vulnerability by sending specially crafted H...

CVE-2024-0538

HIGH CVSS 8.8 Jan 15, 2024

A critical stack-based buffer overflow vulnerability in Tenda W9 routers allows remote attackers to execute arbitrary code by manipulating the ssidIndex parameter in the formQosManage_auto function of...

CVE-2024-0536

HIGH CVSS 8.8 Jan 15, 2024

A critical stack-based buffer overflow vulnerability in Tenda W9 routers allows remote attackers to execute arbitrary code by manipulating the ssidIndex parameter in the setWrlAccessList function of t...