Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · tenda

tenda

· 565 Critical

Total CVEs

1,842

Critical

565

Products

218

Search All CVEs →

1,842

Products (218)

ac6112 CVEsac6 firmware108 CVEsac18 firmware103 CVEsac18101 CVEsac1093 CVEsac992 CVEsac10 firmware92 CVEsac9 firmware92 CVEsac1585 CVEsac15 firmware85 CVEsac768 CVEsac7 firmware68 CVEsw30e firmware63 CVEsfh1202 firmware63 CVEsw30e63 CVEsfh120263 CVEsac8 firmware62 CVEsax1806 firmware61 CVEsax180661 CVEsax1803 firmware60 CVEsax180360 CVEsax3 firmware53 CVEsax353 CVEsac848 CVEsm345 CVEsm3 firmware45 CVEsac1206 firmware44 CVEsac120644 CVEsac540 CVEsac5 firmware40 CVEsch2239 CVEsfh120639 CVEsfh1206 firmware39 CVEsch22 firmware39 CVEsfh1203 firmware35 CVEsfh120335 CVEsf120334 CVEsf1203 firmware34 CVEsw15e33 CVEsax12 firmware31 CVEsax1231 CVEsw15e firmware31 CVEsf45330 CVEsf453 firmware30 CVEsac2129 CVEsfh1205 firmware29 CVEsfh120529 CVEsac21 firmware29 CVEsac23 firmware28 CVEsac2328 CVEsfh45128 CVEsfh451 firmware28 CVEso326 CVEsfh1201 firmware25 CVEsfh120125 CVEsg3 firmware24 CVEsg324 CVEsf1202 firmware24 CVEsf120224 CVEsw20e firmware23 CVEsf45622 CVEsf456 firmware22 CVEsa15 firmware22 CVEsa1522 CVEsw20e21 CVEswh45021 CVEswh450 firmware21 CVEsac20 firmware20 CVEsac2020 CVEsac10u firmware19 CVEsac10u19 CVEsi2119 CVEsi21 firmware19 CVEsw919 CVEsw9 firmware19 CVEsi2217 CVEsi22 firmware17 CVEsrx3 firmware17 CVEsrx317 CVEsf451 firmware16 CVEsac50016 CVEso3 firmware16 CVEsac500 firmware16 CVEsf45116 CVEsw18e15 CVEsw18e firmware15 CVEstx314 CVEstx3 firmware14 CVEsac8v414 CVEs4g30012 CVEs4g300 firmware12 CVEsa18 firmware11 CVEsax911 CVEsi911 CVEsrx2 pro11 CVEsa1811 CVEsrx2 pro firmware11 CVEsi9 firmware11 CVEsax9 firmware11 CVEsi29 firmware10 CVEsw6-s firmware10 CVEsw6-s10 CVEsf310 CVEsf3 firmware10 CVEso3 firmware1.0.0.10\(2478\)10 CVEsi2910 CVEsac11 firmware9 CVEstx9 pro firmware9 CVEsrx9 pro firmware9 CVEsrx9 pro9 CVEsi129 CVEsi12 firmware9 CVEsac119 CVEstx9 pro9 CVEsw6 firmware8 CVEsw68 CVEsi38 CVEsw12 firmware8 CVEsw128 CVEsi3 firmware8 CVEsi67 CVEsw37 CVEscp37 CVEsw3 firmware7 CVEsi6 firmware7 CVEscp3 firmware7 CVEshg97 CVEshg9 firmware7 CVEscx12l firmware6 CVEspw201a6 CVEsi24 firmware6 CVEscx12l6 CVEsa216 CVEsa21 firmware6 CVEsi246 CVEspw201a firmware6 CVEsg103 firmware5 CVEsg1035 CVEsg15 CVEspa2025 CVEsac6v2.0 firmware5 CVEsg1 firmware5 CVEspa202 firmware5 CVEshg3 firmware4 CVEshg104 CVEshg10 firmware4 CVEshg34 CVEso64 CVEso6 firmware4 CVEstx94 CVEstx9 firmware4 CVEsn3013 CVEsac10v43 CVEsac10v4 firmware3 CVEsn301 firmware3 CVEscp3 pro2 CVEsn3002 CVEs4g03 pro2 CVEs4g03 pro firmware2 CVEso12 CVEso1 firmware2 CVEsn300 firmware2 CVEscp3 pro firmware2 CVEso4 firmware1 CVEso51 CVEso5 firmware1 CVEsax2 pro firmware1 CVEsax2 pro1 CVEsa3011 CVEsa301 firmware1 CVEsfh303 firmware1 CVEsfh3031 CVEsa3021 CVEsa302 firmware1 CVEsa321 CVEsa32 firmware1 CVEsa5s1 CVEsa5s firmware1 CVEs11n1 CVEsax12 pro firmware1 CVEsax12 pro1 CVEsac191 CVEsac19 firmware1 CVEsap5001 CVEsd301 firmware1 CVEsd3011 CVEsd151 firmware1 CVEsd1511 CVEscp7 firmware1 CVEs4g06 firmware1 CVEscp71 CVEsw3002r1 CVEsw3002r firmware1 CVEsw308r1 CVEsw308r firmware1 CVEsw309r1 CVEsw309r firmware1 CVEs4g061 CVEscp6 firmware1 CVEscp61 CVEsap500v1 firmware1 CVEswh450a1 CVEswh450a firmware1 CVEs11n firmware1 CVEshg6 firmware1 CVEsit7-lcs firmware1 CVEsit7-lcs1 CVEsit7-pcs1 CVEsit7-pcs firmware1 CVEsit7-prs1 CVEsit7-prs firmware1 CVEshg61 CVEsa3001 CVEsn3 wireless n1501 CVEsg300-f firmware1 CVEsg300-f1 CVEsa300 firmware1 CVEso41 CVEs

Recent Vulnerabilities

View all 1,842
CVE-2026-8265MEDIUM 4.7

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-8264MEDIUM 6.3

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-8263MEDIUM 4.7

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-8259MEDIUM 4.7

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

CVE-2026-8138HIGH 8.8

A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

CVE-2026-7470HIGH 8.8

A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVE-2026-7469MEDIUM 6.3

A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in command injection. The attack may be launched remotely. The exploit is now public and may be used.

CVE-2018-25318CRITICAL 9.8

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS servers and redirect user traffic to malicious sites.

CVE-2018-25317CRITICAL 9.8

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin language cookie to change primary and secondary DNS servers, redirecting user traffic to malicious DNS servers.

CVE-2018-25316CRITICAL 9.8

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS servers and redirect user traffic to malicious sites.

CVE-2026-7160HIGH 8.8

A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVE-2026-7151HIGH 8.8

A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-31255CRITICAL 9.8

A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.

CVE-2026-7119HIGH 8.8

A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.

CVE-2026-7102MEDIUM 6.3

A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacMac of the component httpd. The manipulation of the argument mac results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.

CVE-2026-7101HIGH 8.8

A vulnerability has been found in Tenda F456 1.0.0.5. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

CVE-2026-7100HIGH 8.8

A flaw has been found in Tenda F456 1.0.0.5. The impacted element is the function fromNatlimitof of the file /goform/Natlimit of the component httpd. Executing a manipulation can lead to buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

CVE-2026-7099HIGH 8.8

A vulnerability was detected in Tenda F456 1.0.0.5. The affected element is the function formQuickIndex of the file /goform/QuickIndex of the component httpd. Performing a manipulation of the argument mit_linktype results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.

CVE-2026-7098HIGH 8.8

A security vulnerability has been detected in Tenda F456 1.0.0.5. Impacted is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-7097HIGH 8.8

A weakness has been identified in Tenda F456 1.0.0.5. This issue affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter of the component httpd. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-7096HIGH 8.8

A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_loid results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-7082HIGH 8.8

A flaw has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Executing a manipulation of the argument Go can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.

CVE-2026-7081HIGH 8.8

A vulnerability was detected in Tenda F456 1.0.0.5. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the component httpd. Performing a manipulation of the argument dips results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.

CVE-2026-7080HIGH 8.8

A security vulnerability has been detected in Tenda F456 1.0.0.5. This impacts the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. Such manipulation of the argument delno leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-7079HIGH 8.8

A weakness has been identified in Tenda F456 1.0.0.5. This affects the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. This manipulation of the argument wanmode causes buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

tenda — Vendor | Dragons Community