Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tenda

First CVE: Aug 22, 2014Active for: 12 yearsTotal CVEs: 1,846
69.3
VTI Score
TOP TARGET

Tenda develops a broad portfolio of consumer and small-business networking devices including routers and wireless access points such as the AC6, AC10, and AC18 series, many of which achieve substantial deployment in home and branch-office environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in memory-safety weaknesses including out-of-bounds writes, stack-based buffer overflows, and classic buffer-overflow conditions, alongside command-injection flaws that are endemic to embedded firmware. The exposure recurs across multiple product lines and firmware versions, reflecting the shared architectural foundations and input-handling demands of the embedded networking platform. Defenders should prioritize inventory of affected devices, restrict remote-management access, and treat firmware updates as urgent where available; live exploitation status and current severity figures are shown alongside this summary.

FAUCET AI Generated
1,846
Total CVEs
More Total CVEs than 100% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Tenda over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2014
11 years ago
Most Recent CVE
Jun 19, 2026
35 days ago

Products(218 total)

Top CVEs

Signals from CVEs in this vendor scope (1846 CVEs).

1,846 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-31755CRITICAL
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary c
May 7, 20219.896YESYES
CVE-2020-10987CRITICAL
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
Jul 13, 20209.895YESYES
CVE-2018-14558CRITICAL
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmwar
Oct 30, 20189.873YESNO
CVE-2022-42233CRITICAL
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
Oct 20, 20229.866NOYES
CVE-2022-30023HIGH
Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
Jun 16, 20228.854NONO
CVE-2020-35391MEDIUM
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/Route
Jan 1, 20216.551NOYES
CVE-2015-5995CRITICAL
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin subst
Dec 31, 20159.851NOYES
CVE-2025-9090CRITICAL
A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads
Aug 17, 20259.850NOYES
CVE-2022-32054CRITICAL
Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.
Jul 7, 20229.847NONO
CVE-2014-5246HIGH
The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language
Aug 22, 201410.047NOYES
View all 1,846 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,846 CVEs
9%
53%
37%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local31 (1.7%)
Network1,715 (92.9%)
Unknown2 (0.1%)
Physical0 (0.0%)
Adjacent Network98 (5.3%)
Attack Complexity
Low1,815 (98.3%)
High29 (1.6%)
Unknown2 (0.1%)
User Interaction
None1,805 (97.8%)
Unknown2 (0.1%)
Required39 (2.1%)
Privileges Required
Low597 (32.3%)
High42 (2.3%)
None1,205 (65.3%)
Unknown2 (0.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (1846 CVEs).

CISA KEV
3 CVEs
0.2% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
0.2% of CVEs· 95th percentile
ExploitDB
7 CVEs
0.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tenda.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tenda — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tenda's Products

View all 6 CNAs →

Top CWEs