MidnightBSD

Advisories for tenda

CVE-2014-5246 HIGH

The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
tenda a5s -
tenda a5s_firmware 3.02.05_cn
CVE-2014-7281 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
tenda a32_firmware 5.07.53_cn
tenda a32 -
CVE-2015-5995 HIGH

Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
mediabridge medialink_mwn-wapr300n_firmware *
tenda n3_wireless_n150 *
CVE-2017-14514 MEDIUM

Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a crafted URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
tenda w15e_firmware *
CVE-2017-14515 MEDIUM

Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service (temporary HTTP outage and forced logout) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
tenda w15e_firmware *
CVE-2017-16923 HIGH

Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to execute arbitrary OS commands via a crafted cgi-bin/luci/usbeject?dev_name= GET request from the LAN. This occurs because the "sub_A6E8 usbeject_process_entry" function executes a system function with untrusted input.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
tenda ac18_firmware ac18_kf_v15.03.05.19(6318_)_cn
tenda ac9_firmware ac9_kf_v15.03.05.19(6318_)_cn
tenda ac9_firmware us_ac9v1.0br_v15.03.05.14_multi_td01
tenda ac15_firmware us_ac15v1.0br_v15.03.05.19_multi_td01
tenda ac18_firmware us_ac18v1.0br_v15.03.05.05_multi_td01
tenda ac15_firmware us_ac15v1.0br_v15.03.05.18_multi_td01
CVE-2017-16936 LOW

Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to read arbitrary files via a cgi-bin/luci/request?op=1&path= URI that uses directory traversal sequences after a /usb/ substring.

CVSS 2.0

Severity: LOW

Problem Type: CWE-22,

Products Affected

Vendor Product Version
tenda ac18_firmware ac18_kf_v15.03.05.19(6318_)_cn
tenda ac9_firmware ac9_kf_v15.03.05.19(6318_)_cn
tenda ac9_firmware us_ac9v1.0br_v15.03.05.14_multi_td01
tenda ac15_firmware us_ac15v1.0br_v15.03.05.19_multi_td01
tenda ac18_firmware us_ac18v1.0br_v15.03.05.05_multi_td01
tenda ac15_firmware us_ac15v1.0br_v15.03.05.18_multi_td01
CVE-2018-14558 HIGH

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,CWE-78,

Products Affected

Vendor Product Version
tenda ac9_firmware *
tenda ac7_firmware *
tenda ac10_firmware *
CVE-2018-18706 HIGH

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
tenda ac10_firmware 15.03.06.23_cn
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
tenda ac7_firmware 15.03.06.44_cn
CVE-2018-18707 HIGH

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
tenda ac10_firmware 15.03.06.23_cn
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
tenda ac7_firmware 15.03.06.44_cn
CVE-2018-18708 HIGH

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
tenda ac10_firmware 15.03.06.23_cn
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
tenda ac7_firmware 15.03.06.44_cn
CVE-2018-18709 HIGH

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
tenda ac10_firmware 15.03.06.23_cn
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
tenda ac7_firmware 15.03.06.44_cn
CVE-2018-18727 HIGH

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
tenda ac10_firmware 15.03.06.23_cn
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
tenda ac7_firmware 15.03.06.44_cn
CVE-2018-18728 HIGH

An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
CVE-2018-18729 HIGH

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy to a variable placed on the heap, which can leak sensitive information or even hijack program control flow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
tenda ac10_firmware 15.03.06.23_cn
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
tenda ac7_firmware 15.03.06.44_cn
CVE-2018-18730 HIGH

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
tenda ac10_firmware 15.03.06.23_cn
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
tenda ac7_firmware 15.03.06.44_cn
CVE-2018-18731 HIGH

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
tenda ac10_firmware 15.03.06.23_cn
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
tenda ac7_firmware 15.03.06.44_cn
CVE-2018-18732 HIGH

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
tenda ac10_firmware 15.03.06.23_cn
tenda ac9_firmware 15.03.05.19(6318)_cn
tenda ac18_firmware 15.03.05.19(6318)_cn
tenda ac15_firmware 15.03.05.19_cn
tenda ac7_firmware 15.03.06.44_cn