Tenda AX12 v22.03.01.46CN was discovered to contain a stack overflow via the sub42F69C function at /goform/setMacFilterCfg.
AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
Tenda AX12 v22.03.01.21CN was discovered to contain a stack overflow via the ssid parameter at /goform/fastsettingwifiset .
Tenda AX12 V22.03.01.21CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.
Tenda AX12 V22.03.01.16cn is vulnerable to command injection via goform/fastsettinginternetset.
Tenda AX12 V22.03.01.21CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
Tenda AX12 v22.03.01.21cn was discovered to contain a stack overflow via the lanIp parameter in /goform/AdvSetLanIp.
Tenda AX12 V22.03.01.21CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub42E328 at /goform/SysToolReboot.
Tenda AX12 V22.03.01.21CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub422168 at /goform/WifiExtraSet.
Tenda AX12 v22.03.01.21 was discovered to contain a stack buffer overflow in the function sub422CE4. This vulnerability allows attackers to cause a Denial of Service (DoS) via the strcpy parameter.
Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub42DE00. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.
Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub4327CC. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.
Tenda AX12 v22.03.01.21 was discovered to contain a stack overflow in the function sub42E328. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.
A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21CN in the sub422CE4 function in the goform/setIPv6Status binary file /usr/sbin/httpd via the conType parameter, which causes a Denial of Service.
A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21CN in the sub422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service.
Tenda AX3 v16.03.12.10CN and AX12 22.03.01.2CN was discovered to contain a stack overflow in the function formfastsettingwifiset. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.