The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | a5s | - |
| tenda | a5s_firmware | 3.02.05_cn |
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | a32_firmware | 5.07.53_cn |
| tenda | a32 | - |
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| mediabridge | medialink_mwn-wapr300n_firmware | * |
| tenda | n3_wireless_n150 | * |
Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a crafted URL.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | w15e_firmware | * |
Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service (temporary HTTP outage and forced logout) via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | w15e_firmware | * |
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to execute arbitrary OS commands via a crafted cgi-bin/luci/usbeject?dev_name= GET request from the LAN. This occurs because the "sub_A6E8 usbeject_process_entry" function executes a system function with untrusted input.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac18_firmware | ac18_kf_v15.03.05.19(6318_)_cn |
| tenda | ac9_firmware | ac9_kf_v15.03.05.19(6318_)_cn |
| tenda | ac9_firmware | us_ac9v1.0br_v15.03.05.14_multi_td01 |
| tenda | ac15_firmware | us_ac15v1.0br_v15.03.05.19_multi_td01 |
| tenda | ac18_firmware | us_ac18v1.0br_v15.03.05.05_multi_td01 |
| tenda | ac15_firmware | us_ac15v1.0br_v15.03.05.18_multi_td01 |
Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to read arbitrary files via a cgi-bin/luci/request?op=1&path= URI that uses directory traversal sequences after a /usb/ substring.
CVSS 2.0
Severity: LOW
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac18_firmware | ac18_kf_v15.03.05.19(6318_)_cn |
| tenda | ac9_firmware | ac9_kf_v15.03.05.19(6318_)_cn |
| tenda | ac9_firmware | us_ac9v1.0br_v15.03.05.14_multi_td01 |
| tenda | ac15_firmware | us_ac15v1.0br_v15.03.05.19_multi_td01 |
| tenda | ac18_firmware | us_ac18v1.0br_v15.03.05.05_multi_td01 |
| tenda | ac15_firmware | us_ac15v1.0br_v15.03.05.18_multi_td01 |
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac9_firmware | * |
| tenda | ac7_firmware | * |
| tenda | ac10_firmware | * |
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac10_firmware | 15.03.06.23_cn |
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
| tenda | ac7_firmware | 15.03.06.44_cn |
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac10_firmware | 15.03.06.23_cn |
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
| tenda | ac7_firmware | 15.03.06.44_cn |
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac10_firmware | 15.03.06.23_cn |
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
| tenda | ac7_firmware | 15.03.06.44_cn |
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "firewallEn" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac10_firmware | 15.03.06.23_cn |
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
| tenda | ac7_firmware | 15.03.06.44_cn |
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac10_firmware | 15.03.06.23_cn |
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
| tenda | ac7_firmware | 15.03.06.44_cn |
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy to a variable placed on the heap, which can leak sensitive information or even hijack program control flow.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac10_firmware | 15.03.06.23_cn |
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
| tenda | ac7_firmware | 15.03.06.44_cn |
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac10_firmware | 15.03.06.23_cn |
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
| tenda | ac7_firmware | 15.03.06.44_cn |
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac10_firmware | 15.03.06.23_cn |
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
| tenda | ac7_firmware | 15.03.06.44_cn |
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tenda | ac10_firmware | 15.03.06.23_cn |
| tenda | ac9_firmware | 15.03.05.19(6318)_cn |
| tenda | ac18_firmware | 15.03.05.19(6318)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn |
| tenda | ac7_firmware | 15.03.06.44_cn |