Vulnerabilities
Vulnerable Software
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-01-22
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote code execution.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-01-21
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-01-21
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-01-21
Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corruption and enable remote code execution (RCE).
CVSS Score
6.5
EPSS Score
0.001
Published
2025-12-08
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
CVSS Score
8.8
EPSS Score
0.0
Published
2024-02-20
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
CVSS Score
9.8
EPSS Score
0.026
Published
2024-01-04
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-12-07
Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-12-07
Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-08-25


Contact Us

Shodan ® - All rights reserved