Tendacn manufactures a focused line of networking and wireless access devices, including the G3, AC6, and AC10U product families, whose vulnerability profile concentrates on memory-safety and command-injection flaws endemic to embedded firmware. Despite a modest product count, the vendor commands substantial prominence in the landscape due to the widespread deployment of its consumer and small-business networking appliances, and vulnerabilities affecting these devices skew strongly toward critical-severity outcomes. The durable exposure pattern reflects the memory-unsafe implementation and OS-level access inherent in router and access-point firmware: out-of-bounds writes, stack-based buffer overflows, classic buffer overflows, and OS command injection recur across product lines and versions. Defenders should prioritize inventory and lifecycle tracking of affected devices, particularly older models that may lack firmware-update paths, as the critical severity of this vendor's disclosures elevates the risk of unauthenticated remote compromise. Live exploitation activity, KEV status, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tendacn over time
Signals from CVEs in this vendor scope (146 CVEs).
146 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5767CRITICAL An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter f | Feb 15, 2018 | 9.8 | 68 | NO | YES |
CVE-2022-31446CRITICAL Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac. | Jun 14, 2022 | 9.8 | 40 | NO | NO |
CVE-2021-27691CRITICAL Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN o | Apr 16, 2021 | 9.8 | 39 | NO | NO |
CVE-2022-32386CRITICAL Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan. | Jul 6, 2022 | 9.8 | 38 | NO | NO |
CVE-2021-44352CRITICAL A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind. | Dec 3, 2021 | 9.8 | 37 | NO | NO |
CVE-2023-44018CRITICAL Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function. | Sep 27, 2023 | 9.8 | 36 | NO | NO |
CVE-2022-32385CRITICAL Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote). | Jul 6, 2022 | 9.8 | 34 | NO | NO |
CVE-2024-0930CRITICAL A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function fromSetWirelessRepeat. The manipulation of the argument wpap | Jan 26, 2024 | 9.8 | 33 | NO | NO |
CVE-2020-22079CRITICAL Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to g | Oct 29, 2021 | 9.8 | 33 | NO | NO |
CVE-2024-46628CRITICAL Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount func | Sep 26, 2024 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (146 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tendacn.
Media articles that mention a CVE ID that affects a product developed by Tendacn — matched by CVE ID, not by vendor name.