Vendor
Remote Stack-Based Buffer Overflow in Tenda W20E
1 TTP 1 CVEA stack-based buffer overflow in the Tenda W20E formDelWebAuthWhiteUser function allows remote unauthenticated attackers to execute arbitrary code or cause a denial of service via manipulation of the webAuthWhiteUserIndex argument.
Authentication Bypass in Tenda AC9 Web Management
1 TTPA critical authentication bypass vulnerability, CVE-2026-86300, exists in the Tenda AC9 firmware version 15.03.05.14, allowing remote attackers to circumvent security controls via the Web Management interface.
Remote Command Injection Vulnerability in Tenda CP3
2 TTPs 1 CVEAn unauthenticated remote command injection vulnerability in Tenda CP3 firmware version 27.5.57.101 allows attackers to execute arbitrary system commands via the AlarmVoiceURL argument.
Critical Authentication Bypass in Tenda AC18 Telnet Handler
1 TTP 1 CVEA critical authentication bypass vulnerability in the Tenda AC18 router allows remote, unauthenticated attackers to gain unauthorized access via the Telnet service.
Authentication Bypass in Tenda AC1206 Web UI
1 rule 1 TTP 1 CVETenda AC1206 firmware version 15.03.06.23 contains an authentication bypass vulnerability in the /goform/telnet handler, allowing remote attackers to gain unauthorized access.
Buffer Overflow Vulnerability in Tenda HG10 Boa Web Server
2 rules 1 TTP 1 CVEA critical buffer overflow vulnerability (CVE-2026-82542) in the Boa Web Server component of Tenda HG10 allows remote unauthenticated attackers to trigger a crash or achieve code execution via the formIPv6Routing function.
Remote Command Injection in Tenda CH22 Firmware
2 rules 3 TTPs 1 CVETenda CH22 router firmware version 1.0.0.1 is vulnerable to unauthenticated remote command injection via the /goform/editFileName endpoint, allowing potential full system compromise.
Authentication Bypass in Tenda AC10 Router
1 TTP 1 CVEAn improper authentication vulnerability in the Tenda AC10 router's httpd component allows remote, unauthenticated attackers to gain unauthorized access to the device.
Remote Stack-Based Buffer Overflow in Tenda W20E
1 rule 2 TTPs 1 CVETenda W20E firmware version 15.11.0.6(1068_1546_841)_CN_TDC contains a stack-based buffer overflow in the /goform/addIpMacBind function, allowing for remote exploitation via the IPMacBindRule argument.
Remote Stack-Based Buffer Overflow in Tenda W20E
2 rules 3 TTPs 1 CVEA stack-based buffer overflow vulnerability in Tenda W20E firmware allows authenticated remote attackers to achieve potential code execution via the QoS Edit component.
Remote Buffer Overflow in Tenda AC12 Web Management Interface
1 rule 1 TTP 1 CVETenda AC12 router firmware contains a buffer overflow vulnerability in the httpd web management interface, allowing remote attackers to trigger arbitrary code execution via a manipulated reboot parameter.
Remote Buffer Overflow Vulnerability in Tenda G0
1 rule 1 TTP 1 CVETenda G0 devices contain a remote buffer overflow vulnerability in the httpd management interface that allows for potential arbitrary code execution or denial of service.
Stack-Based Buffer Overflow in Tenda AC1206 Web Interface
1 rule 1 TTP 1 CVEA stack-based buffer overflow in the Tenda AC1206 firmware version 15.03.06.23_multi_TD01 allows remote attackers to trigger memory corruption via the httpd web management interface.
Command Injection Vulnerability in Tenda Smart Camera ATE Module
2 TTPs 1 CVEMultiple Tenda smart camera models are susceptible to unauthenticated remote command injection via the 'CAte::HandleCmd' function, allowing attackers to execute arbitrary system commands.
Remote Command Injection in Tenda CH22
1 rule 2 TTPs 1 CVETenda CH22 firmware version 1.0.0.1 is vulnerable to unauthenticated remote command injection via the formCertListInfo function, allowing for arbitrary system command execution.
Critical Stack Overflow in Tenda W6-S wifiSSIDset Endpoint
1 rule 2 TTPs 1 CVE 1 IOCA critical stack-based buffer overflow in the Tenda W6-S web management interface allows unauthenticated remote attackers to cause a denial of service or potentially execute arbitrary code.
Tenda AC10 Buffer Overflow Vulnerability (CVE-2026-16248)
2 TTPs 1 CVE 6 IOCsA stack-based buffer overflow vulnerability (CVE-2026-16248) has been identified in Tenda AC10 firmware version 16.03.10.09_multi_TDE01, residing in the fromAdvSetLanip function of the /goform/AdvSetLanip file within the httpd/netctrl component, which can be remotely exploited by manipulating the GetValue/SetValue argument, with a public exploit now available.
CVE-2026-15692: Tenda BE12 Pro Stack-Based Buffer Overflow Vulnerability
1 rule 2 TTPs 1 CVE 6 IOCsA stack-based buffer overflow vulnerability, identified as CVE-2026-15692, exists in Tenda BE12 Pro firmware version 16.03.66.23's `fromSafeUrlFilter` function, allowing remote attackers to achieve arbitrary code execution by manipulating the 'page' argument via a crafted HTTP request, with a public exploit available.
Tenda BE12 Pro Remote Code Execution Vulnerability (CVE-2026-15691)
2 TTPs 5 CVEs 8 IOCsA critical remote stack-based buffer overflow vulnerability (CVE-2026-15691) has been discovered in Tenda BE12 Pro firmware 16.03.66.23, affecting the `fromSafeClientFilter` function and allowing remote attackers to achieve arbitrary code execution by manipulating the `page` argument, with a public exploit available.
Critical Buffer Overflow in Tenda CH22 Leads to Remote Code Execution (CVE-2026-15543)
1 TTP 1 CVEA critical buffer overflow vulnerability, CVE-2026-15543, exists in the Tenda CH22 1.0.0.1 firmware's `formCertListInfo` function, allowing unauthenticated remote attackers to achieve arbitrary code execution by manipulating the 'Name' argument, with a public exploit available.
UAT-7810 Expands ORB Networks with New Malware; ARToken Phishing-as-a-Service and Device Vulnerabilities Highlighted
10 TTPs 8 IOCsThe China-nexus threat actor UAT-7810 is expanding its Operational Relay Box (ORB) networks by exploiting known vulnerabilities in unpatched Ruckus and ASUS routers to deploy custom backdoors like LONGLEASH and DOGLEASH, while other threats include the ARToken Phishing-as-a-Service platform targeting Microsoft 365, critical flaws in AirDrop/Quick Share, and a backdoor in Tenda router firmware.
CVE-2026-10192 - Tenda W12 Stack-Based Buffer Overflow in set_local_time_0
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability exists in Tenda W12 version 3.0.0.7(4763) in the `set_local_time_0` function, which allows a remote attacker to execute arbitrary code by manipulating the Time argument.
Tenda F1202 Stack-Based Buffer Overflow Vulnerability (CVE-2026-9431)
2 rules 1 TTP 1 CVEA remote stack-based buffer overflow vulnerability (CVE-2026-9431) exists in the fromPptpUserAdd function of the /goform/PptpUserAdd file in Tenda F1202 firmware version 1.2.0.20(408), allowing unauthenticated attackers to potentially execute arbitrary code.
Tenda F1202 Stack-Based Buffer Overflow Vulnerability (CVE-2026-9430)
2 rules 2 TTPs 1 CVEA stack-based buffer overflow vulnerability (CVE-2026-9430) exists in Tenda F1202 version 1.2.0.20(408) due to manipulation of the 'dips' argument in the 'formGstDhcpSetSer' function of '/goform/GstDhcpSetSerof', allowing remote code execution.
Tenda F1202 Stack-Based Buffer Overflow Vulnerability (CVE-2026-9429)
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability (CVE-2026-9429) exists in Tenda F1202 version 1.2.0.20(408) within the formWrlExtraSet function of the /goform/WrlExtraSet file, allowing a remote attacker to execute arbitrary code by manipulating the delno argument; a public exploit is available.
Tenda CX12L Stack-Based Buffer Overflow Vulnerability (CVE-2026-8138)
2 rules 2 TTPs 1 CVETenda CX12L router version 16.03.53.12 is vulnerable to a stack-based buffer overflow in the formSetPPTPServer function of /goform/SetPptpServerCfg, allowing remote attackers to execute arbitrary code.
Tenda 4G300 Stack-Based Buffer Overflow Vulnerability
2 rules 2 TTPs 1 CVEA remote stack-based buffer overflow vulnerability exists in the Tenda 4G300 router, version US_4G300V1.0Mt_V1.01.42_CN_TDC01, allowing an attacker to potentially execute arbitrary code by manipulating the 'page' argument to the sub_427C3C function in the /goform/SafeMacFilter file.
Tenda W308R DNS Hijacking Vulnerability (CVE-2018-25316)
2 rules 1 TTP 1 CVETenda W308R v2 V5.07.48 is vulnerable to cookie session weakness, allowing unauthenticated attackers to modify DNS settings via crafted GET requests to redirect user traffic to malicious sites.
Tenda Router DNS Hijacking via Cookie Session Weakness
2 rules 1 TTP 1 CVETenda W3002R/A302/W309R routers with firmware V5.07.64_en are vulnerable to unauthenticated DNS hijacking, where attackers exploit a cookie session weakness to modify DNS settings via crafted GET requests.
Tenda HG3 v2.0 Stack-Based Buffer Overflow in formUploadConfig
2 rules 2 TTPs 1 CVEA stack-based buffer overflow vulnerability in the formUploadConfig function of Tenda HG3 v2.0's /boaform/formIPv6Routing file allows remote attackers to execute arbitrary code by manipulating the destNet argument.
Tenda HG3 2.0 Command Injection Vulnerability
2 rules 1 TTP 1 CVETenda HG3 2.0 is vulnerable to command injection; by manipulating the datasize argument in the formTracert function of the /boaform/formTracert file, a remote attacker can inject commands.
Tenda F456 Router Buffer Overflow Vulnerability (CVE-2026-7101)
2 rules 1 TTP 1 CVEA buffer overflow vulnerability in Tenda F456 version 1.0.0.5 allows remote attackers to execute arbitrary code via a crafted request to the fromWrlclientSet function in the /goform/WrlclientSet file of the httpd component.
Tenda F456 Router Buffer Overflow Vulnerability
2 rules 1 TTP 1 CVEA buffer overflow vulnerability exists in Tenda F456 version 1.0.0.5 in the `fromGstDhcpSetSer` function, allowing remote attackers to execute arbitrary code by manipulating the 'dips' argument via a crafted HTTP request to `/goform/GstDhcpSetSer`.
Tenda i9 Path Traversal Vulnerability (CVE-2026-7036)
2 rules 1 TTP 1 CVECVE-2026-7036 is a path traversal vulnerability affecting the R7WebsSecurityHandlerfunction in the HTTP Handler component of Tenda i9 version 1.0.0.5(2204), allowing remote attackers to access sensitive files.
Tenda F456 Router Buffer Overflow Vulnerability
2 rules 1 TTP 1 CVEA buffer overflow vulnerability in Tenda F456 router version 1.0.0.5 allows a remote attacker to execute arbitrary code by exploiting the fromSafeClientFilter function in the /goform/SafeClientFilter endpoint through manipulation of the 'menufacturer/Go' argument.
Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon Buffer Overflow Vulnerability
2 rules 1 TTP 1 CVEA buffer overflow vulnerability in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon allows remote attackers to execute arbitrary code by manipulating the nextHop argument in the formRoute function of the /boaform/formRouting file, impacting device availability and integrity.
Tenda F453 Router Stack-Based Buffer Overflow Vulnerability
2 rules 1 TTPA stack-based buffer overflow vulnerability (CVE-2026-4552) exists in the Tenda F453 router version 1.0.0.3, allowing remote attackers to execute arbitrary code by manipulating the 'page' argument in the /goform/VirtualSer endpoint, due to insufficient input validation in the fromVirtualSer function.
Tenda CH22 Path Traversal Vulnerability (CVE-2026-5962)
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in Tenda CH22 version 1.0.0.6(468), affecting the R7WebsSecurityHandler function within the httpd component, allowing remote attackers to access sensitive files.
Tenda F451 Stack-Based Buffer Overflow Vulnerability (CVE-2026-5992)
2 rules 1 TTP 1 CVETenda F451 version 1.0.0.7 is vulnerable to a stack-based buffer overflow in the fromP2pListFilter function, allowing remote attackers to execute arbitrary code by manipulating the 'page' argument in the /goform/P2pListFilter file.
Tenda FH303/A300 DNS Hijacking Vulnerability (CVE-2018-25318)
2 rules 1 TTP 1 CVETenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability (CVE-2018-25318) that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation, potentially redirecting user traffic to malicious sites.
Tenda HG3 Router Command Injection Vulnerability (CVE-2026-7096)
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-7096) exists in the Tenda HG3 2.0 300003070 router, allowing remote attackers to execute arbitrary OS commands by manipulating the 'fmgpon_loid' argument in the 'formgponConf' function of the '/boaform/admin/formgponConf' file due to insufficient input validation.
Tenda F453 Stack-Based Buffer Overflow Vulnerability
2 rules 1 TTPA stack-based buffer overflow vulnerability (CVE-2026-4551) exists in Tenda F453 version 1.0.0.3, allowing remote attackers to execute arbitrary code by manipulating the 'menufacturer/Go' argument in the fromSafeClientFilter function.
Tenda AC5 Stack-Based Buffer Overflow Vulnerability (CVE-2026-4906)
3 rules 1 TTPA stack-based buffer overflow vulnerability exists in Tenda AC5 version 15.03.06.47 allowing remote attackers to execute arbitrary code by manipulating the WANT/WANS argument in a POST request to /goform/WizardHandle.
Tenda FH1202 Stack-Based Buffer Overflow Vulnerability (CVE-2026-7034)
1 rule 1 TTP 1 CVEA stack-based buffer overflow vulnerability exists in the Tenda FH1202 router, specifically in the WrlExtraSet function, allowing remote attackers to execute arbitrary code by manipulating the 'Go' argument in a request to /goform/WrlExtraSet.
Tenda F456 Remote Buffer Overflow Vulnerability
2 rules 1 TTP 1 CVEA remote buffer overflow vulnerability exists in Tenda F456 version 1.0.0.5 via manipulation of the 'page' argument in the fromDhcpListClient function of the /goform/DhcpListClient component, potentially leading to arbitrary code execution.
Tenda AC5 Router Stack-Based Buffer Overflow (CVE-2026-4904)
2 rules 2 TTPsA stack-based buffer overflow vulnerability (CVE-2026-4904) exists in the Tenda AC5 router version 15.03.06.47, allowing remote attackers to execute arbitrary code by manipulating the 'funcpara1' argument in the '/goform/setcfm' endpoint.