A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18multi.
An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18multi. When the condition is met, s11 will be passed into subB0488, concatenated into doSystemCmd. The value of s11 is not validated, potentially leading to a command injection vulnerability.
A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18multi device via the list parameter in a post request in goform/SetIpMacBind.