Tenda develops a broad portfolio of consumer and small-business networking devices including routers and wireless access points such as the AC6, AC10, and AC18 series, many of which achieve substantial deployment in home and branch-office environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in memory-safety weaknesses including out-of-bounds writes, stack-based buffer overflows, and classic buffer-overflow conditions, alongside command-injection flaws that are endemic to embedded firmware. The exposure recurs across multiple product lines and firmware versions, reflecting the shared architectural foundations and input-handling demands of the embedded networking platform. Defenders should prioritize inventory of affected devices, restrict remote-management access, and treat firmware updates as urgent where available; live exploitation status and current severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tenda over time
Signals from CVEs in this vendor scope (1846 CVEs).
1,846 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31755CRITICAL An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary c | May 7, 2021 | 9.8 | 96 | YES | YES |
CVE-2020-10987CRITICAL The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter. | Jul 13, 2020 | 9.8 | 95 | YES | YES |
CVE-2018-14558CRITICAL An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmwar | Oct 30, 2018 | 9.8 | 73 | YES | NO |
CVE-2022-42233CRITICAL Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability. | Oct 20, 2022 | 9.8 | 66 | NO | YES |
CVE-2022-30023HIGH Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function. | Jun 16, 2022 | 8.8 | 54 | NO | NO |
CVE-2020-35391MEDIUM Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/Route | Jan 1, 2021 | 6.5 | 51 | NO | YES |
CVE-2015-5995CRITICAL Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin subst | Dec 31, 2015 | 9.8 | 51 | NO | YES |
CVE-2025-9090CRITICAL A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads | Aug 17, 2025 | 9.8 | 50 | NO | YES |
CVE-2022-32054CRITICAL Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter. | Jul 7, 2022 | 9.8 | 47 | NO | NO |
CVE-2014-5246HIGH The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language | Aug 22, 2014 | 10.0 | 47 | NO | YES |
Signals from CVEs in this vendor scope (1846 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tenda.
Media articles that mention a CVE ID that affects a product developed by Tenda — matched by CVE ID, not by vendor name.