Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tendacn

First CVE: May 21, 2017Active for: 9 yearsTotal CVEs: 146
48.7
VTI Score
High

Tendacn manufactures a focused line of networking and wireless access devices, including the G3, AC6, and AC10U product families, whose vulnerability profile concentrates on memory-safety and command-injection flaws endemic to embedded firmware. Despite a modest product count, the vendor commands substantial prominence in the landscape due to the widespread deployment of its consumer and small-business networking appliances, and vulnerabilities affecting these devices skew strongly toward critical-severity outcomes. The durable exposure pattern reflects the memory-unsafe implementation and OS-level access inherent in router and access-point firmware: out-of-bounds writes, stack-based buffer overflows, classic buffer overflows, and OS command injection recur across product lines and versions. Defenders should prioritize inventory and lifecycle tracking of affected devices, particularly older models that may lack firmware-update paths, as the critical severity of this vendor's disclosures elevates the risk of unauthenticated remote compromise. Live exploitation activity, KEV status, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
146
Total CVEs
More Total CVEs than 99% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tendacn over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 21, 2017
9 years ago
Most Recent CVE
Mar 14, 2025
497 days ago

Products(48 total)

Top CVEs

Signals from CVEs in this vendor scope (146 CVEs).

146 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5767CRITICAL
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter f
Feb 15, 20189.868NOYES
CVE-2022-31446CRITICAL
Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.
Jun 14, 20229.840NONO
CVE-2021-27691CRITICAL
Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN o
Apr 16, 20219.839NONO
CVE-2022-32386CRITICAL
Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
Jul 6, 20229.838NONO
CVE-2021-44352CRITICAL
A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in goform/SetIpMacBind.
Dec 3, 20219.837NONO
CVE-2023-44018CRITICAL
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function.
Sep 27, 20239.836NONO
CVE-2022-32385CRITICAL
Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).
Jul 6, 20229.834NONO
CVE-2024-0930CRITICAL
A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function fromSetWirelessRepeat. The manipulation of the argument wpap
Jan 26, 20249.833NONO
CVE-2020-22079CRITICAL
Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to g
Oct 29, 20219.833NONO
CVE-2024-46628CRITICAL
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount func
Sep 26, 20249.832NONO
View all 146 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products146 CVEs
45%
51%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (2.7%)
Network137 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (3.4%)
Attack Complexity
Low145 (99.3%)
High1 (0.7%)
Unknown0 (0.0%)
User Interaction
None143 (97.9%)
Unknown0 (0.0%)
Required3 (2.1%)
Privileges Required
Low16 (11.0%)
High2 (1.4%)
None128 (87.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (146 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tendacn.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tendacn — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tendacn's Products

View all 3 CNAs →

Top CWEs