Tenda
Tenda Technology is a global networking hardware vendor focused on consumer and SMB-grade routers, switches, and related network devices, delivering affordable, mass-market connectivity solutions.
- Total products in the ecosystem
- 71
en
Tenda Technology is a global networking hardware vendor focused on consumer and SMB-grade routers, switches, and related network devices, delivering affordable, mass-market connectivity solutions.
As of 10/05/2026, Tenda recorded 46 security vulnerabilities in the last 90 days across 25 products, including 39 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, CP3 had the most security vulnerabilities in the Tenda ecosystem, with 9 vulnerabilities—approximately 19.57% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-104611Tenda AC9 POST Request fast_setting_internet_set stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC9 | Published10/02/2026 | SeverityCritical |
CVE-2026-104610Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG7 | Published10/02/2026 | SeverityCritical |
CVE-2026-90689Tenda W20E formDelWebAuthWhiteUser stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Affected productW20E | Published09/14/2026 | SeverityHigh |
CVE-2026-90688Tenda W20E HTTP formIPMacBindAdd stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW20E | Published09/14/2026 | SeverityHigh |
CVE-2026-86300Tenda AC9 Web Management R7WebsSecurityHandler improper authentication | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC9 | Published09/07/2026 | SeverityMedium |
CVE-2026-86167Tenda HG10 Boa formgponConf os command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG10 | Published09/06/2026 | SeverityCritical |
CVE-2026-86166Tenda HG10 Boa Web Server formWanRedirect buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG10 | Published09/06/2026 | SeverityHigh |
CVE-2026-86165Tenda HG10 formURL buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG10 | Published09/06/2026 | SeverityCritical |
CVE-2026-86153Tenda CP3 Redirect.cpp SetRedirectEnable privileges management | Exploitation statusNot known exploited | FixNot confirmed | Affected productCP3 | Published09/06/2026 | SeverityCritical |
CVE-2026-86152Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection | Exploitation statusNot known exploited | FixNot confirmed | Affected productCP3 | Published09/06/2026 | SeverityCritical |
CVE-2026-86151Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productCP3 | Published09/05/2026 | SeverityCritical |
CVE-2026-86150Tenda CP3 hostapd hard-coded credentials | Exploitation statusNot known exploited | FixNot confirmed | Affected productCP3 | Published09/05/2026 | SeverityMedium |
CVE-2026-86149Tenda CP3 NetCheckPing.cpp os command injection | Exploitation statusNot known exploited | FixNot confirmed | Affected productCP3 | Published09/05/2026 | SeverityCritical |
CVE-2026-86148Tenda CP3 Kylin system.c SystemAsh os command injection | Exploitation statusNot known exploited | FixNot confirmed | Affected productCP3 | Published09/05/2026 | SeverityCritical |
CVE-2026-85110Tenda HG10 Boa Web Server formWlanSetup buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG10 | Published09/03/2026 | SeverityHigh |
CVE-2026-85109Tenda HG10 Boa Web Server formLogin buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG10 | Published09/03/2026 | SeverityCritical |
CVE-2026-82695Tenda AC18 Telnet telnet missing authentication | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC18 | Published08/31/2026 | SeverityCritical |
CVE-2026-82694Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC1206 | Published08/31/2026 | SeverityCritical |
CVE-2026-82693Tenda AC1206 Web UI telnet TendaTelnet missing authentication | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC1206 | Published08/31/2026 | SeverityCritical |
CVE-2026-82542Tenda HG10 Boa Web Server formIPv6Routing buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG10 | Published08/30/2026 | SeverityCritical |
CVE-2026-78141Tenda CH22 exeCommand formexeCommand command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productCH22 | Published08/23/2026 | SeverityMedium |
CVE-2026-78063Tenda CH22 editFileName formeditFileName command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productCH22 | Published08/23/2026 | SeverityMedium |
CVE-2026-77031Tenda CH22 formcreateFileName command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productCH22 | Published08/20/2026 | SeverityMedium |
CVE-2026-19924Tenda AC10 httpd R7WebsSecurityHandler improper authentication | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC10 | Published08/16/2026 | SeverityCritical |
CVE-2026-19824Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW20E | Published08/14/2026 | SeverityHigh |
CVE-2026-19823Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW20E | Published08/14/2026 | SeverityHigh |
CVE-2026-19822Tenda W20E QoS Edit editQos lstAdd stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW20E | Published08/14/2026 | SeverityHigh |
CVE-2026-19821Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC12 | Published08/14/2026 | SeverityHigh |
CVE-2026-19792Tenda G0 httpd web management interface module setPortMapping buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productG0 | Published08/14/2026 | SeverityHigh |
CVE-2026-19791Tenda G0 httpd web management interface module addStaticRoute stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productG0 | Published08/14/2026 | SeverityHigh |
CVE-2026-19790Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productG0 | Published08/14/2026 | SeverityHigh |
CVE-2026-19789Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC1206 | Published08/14/2026 | SeverityHigh |
CVE-2026-19788Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC1206 | Published08/14/2026 | SeverityHigh |
CVE-2026-19750Tenda CH/CP/TX3 SSH hard-coded password | Exploitation statusPublic exploit | FixNot confirmed | Affected productCH | Published08/13/2026 | SeverityCritical |
CVE-2026-19749Tenda CH7 RTSP/ONVIF missing authentication | Exploitation statusPublic exploit | FixNot confirmed | Affected productCH7 | Published08/13/2026 | SeverityMedium |
CVE-2026-19748Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy | Exploitation statusPublic exploit | FixNot confirmed | Affected productCH7 | Published08/13/2026 | SeverityMedium |
CVE-2026-19747Tenda CH7 ATE Module Kylin HandleCmd command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productCH7 | Published08/13/2026 | SeverityCritical |
CVE-2026-19346Tenda CH22 CertListInfo formCertListInfo command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productCH22 | Published08/09/2026 | SeverityHigh |
CVE-2026-16248Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC10 | Published07/20/2026 | SeverityHigh |
CVE-2026-15696Tenda BE12 Pro VirtualSer fromVirtualSer stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productBE12 Pro | Published07/14/2026 | SeverityHigh |
CVE-2026-15695Tenda BE12 Pro DhcpListClient fromDhcpListClient stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productBE12 Pro | Published07/14/2026 | SeverityHigh |
CVE-2026-15694Tenda BE12 Pro SetIpBind fromSetIpBind stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productBE12 Pro | Published07/14/2026 | SeverityHigh |
CVE-2026-15693Tenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productBE12 Pro | Published07/14/2026 | SeverityHigh |
CVE-2026-15692Tenda BE12 Pro SafeUrlFilter fromSafeUrlFilter stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productBE12 Pro | Published07/14/2026 | SeverityHigh |
CVE-2026-15691Tenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productBE12 Pro | Published07/14/2026 | SeverityHigh |
CVE-2026-15543Tenda CH22 CertListInfo formCertListInfo buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productCH22 | Published07/13/2026 | SeverityHigh |
CVE-2026-11405Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface | Exploitation statusNot known exploited | FixNot confirmed | Affected productfirmware | Published07/06/2026 | SeverityCritical |
CVE-2026-13519Tenda JD12L NatStaticSetting fromNatStaticSetting stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productJD12L | Published06/29/2026 | SeverityHigh |
CVE-2026-13518Tenda JD12L addressNat fromAddressNat stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productJD12L | Published06/29/2026 | SeverityHigh |
CVE-2026-13517Tenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productJD12L | Published06/29/2026 | SeverityHigh |
CVE-2026-13516Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productJD12L | Published06/28/2026 | SeverityHigh |
CVE-2026-13515Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productJD12L | Published06/28/2026 | SeverityHigh |
CVE-2026-11557Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF451 | Published06/08/2026 | SeverityHigh |
CVE-2026-11556Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productF451 | Published06/08/2026 | SeverityHigh |
CVE-2026-11553Tenda HG7/HG9/HG10 formPPPEdit stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG7 | Published06/08/2026 | SeverityHigh |
CVE-2026-11528Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC18 | Published06/08/2026 | SeverityHigh |
CVE-2026-11524Tenda W20E Web Management modifyWifiFilterRules stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW20E | Published06/08/2026 | SeverityHigh |
CVE-2026-11523Tenda W20E Web Management PortalAuth formPortalAuth stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW20E | Published06/08/2026 | SeverityHigh |
CVE-2026-11522Tenda W20E setPortMirror formSetPortMirror stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW20E | Published06/08/2026 | SeverityHigh |
CVE-2026-11504Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productCX12L | Published06/08/2026 | SeverityHigh |
CVE-2026-11503Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productCX12L | Published06/08/2026 | SeverityHigh |
CVE-2026-11499Tenda HG7/HG9/HG10 formDOMAINBLK stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Affected productHG7 | Published06/08/2026 | SeverityCritical |
CVE-2026-11498Tenda HG7/HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow | Exploitation statusNot known exploited | FixNot confirmed | Affected productHG7 | Published06/08/2026 | SeverityHigh |
CVE-2026-11493Tenda AC15 Samba smb.conf weak password | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC15 | Published06/08/2026 | SeverityLow |
CVE-2026-10192Tenda W12 httpd set_local_time_0 stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW12 | Published05/31/2026 | SeverityHigh |
CVE-2026-10191Tenda W12 httpd cgiWifiMacFilterSet stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW12 | Published05/31/2026 | SeverityHigh |
CVE-2026-10190Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service | Exploitation statusPublic exploit | FixNot confirmed | Affected productW12 | Published05/31/2026 | SeverityHigh |
CVE-2026-10189Tenda W12 httpd cgiSysTimeInfoSet stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW12 | Published05/31/2026 | SeverityHigh |
CVE-2026-10188Tenda W12 httpd cgistaKickOff stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productW12 | Published05/31/2026 | SeverityHigh |
CVE-2026-9431Tenda F1202 PptpUserAdd fromPptpUserAdd stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF1202 | Published05/25/2026 | SeverityHigh |
CVE-2026-9430Tenda F1202 GstDhcpSetSerof formGstDhcpSetSer stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF1202 | Published05/25/2026 | SeverityHigh |
CVE-2026-9429Tenda F1202 WrlExtraSet formWrlExtraSet stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF1202 | Published05/25/2026 | SeverityHigh |
CVE-2026-9428Tenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF1202 | Published05/25/2026 | SeverityHigh |
CVE-2026-9389Tenda F456 L7Im frmL7ImForm buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published05/24/2026 | SeverityHigh |
CVE-2026-8265Tenda AC6 httpd getLogFile get_log_file os command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC6 | Published05/11/2026 | SeverityMedium |
CVE-2026-8264Tenda AC6 httpd WifiApScan formWifiApScan os command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC6 | Published05/11/2026 | SeverityMedium |
CVE-2026-8263Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC6 | Published05/11/2026 | SeverityMedium |
CVE-2026-8259Tenda AC6 httpd telnet os command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productAC6 | Published05/11/2026 | SeverityMedium |
CVE-2026-8138Tenda CX12L SetPptpServerCfg” formSetPPTPServer stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productCX12L | Published05/08/2026 | SeverityHigh |
CVE-2026-7470Tenda 4G300 SafeMacFilter sub_427C3C stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected product4G300 | Published04/30/2026 | SeverityHigh |
CVE-2026-7469Tenda 4G300 DelFil sub_425A28 command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected product4G300 | Published04/30/2026 | SeverityMedium |
CVE-2018-25318Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change | Exploitation statusPublic exploit | FixNot confirmed | Affected productFH303/A300 | Published04/29/2026 | SeverityCritical |
CVE-2018-25317Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change | Exploitation statusPublic exploit | FixNot confirmed | Affected productW3002R | Published04/29/2026 | SeverityCritical |
CVE-2018-25316Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change | Exploitation statusPublic exploit | FixNot confirmed | Affected productW308R v2 | Published04/29/2026 | SeverityCritical |
CVE-2026-7160Tenda HG3 formTracert command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG3 | Published04/27/2026 | SeverityHigh |
CVE-2026-7151Tenda HG3 formIPv6Routing formUploadConfig stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG3 | Published04/27/2026 | SeverityHigh |
CVE-2026-7119Tenda HG3 formCountrystr os command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG3 | Published04/27/2026 | SeverityHigh |
CVE-2026-7102Tenda F456 httpd WriteFacMac FromWriteFacMac command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityMedium |
CVE-2026-7101Tenda F456 httpd WrlclientSet fromWrlclientSet buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7100Tenda F456 httpd Natlimit fromNatlimitof buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7099Tenda F456 httpd QuickIndex formQuickIndex buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7098Tenda F456 httpd DhcpListClient fromDhcpListClient buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7097Tenda F456 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7096Tenda HG3 formgponConf os command injection | Exploitation statusPublic exploit | FixNot confirmed | Affected productHG3 | Published04/27/2026 | SeverityHigh |
CVE-2026-7082Tenda F456 httpd WrlExtraSet formWrlExtraSet buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7081Tenda F456 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7080Tenda F456 httpd PPTPUserSetting fromPPTPUserSetting buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7079Tenda F456 httpd AdvSetWan fromAdvSetWan buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7078Tenda F456 httpd SetIpBind fromSetIpBind buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/27/2026 | SeverityHigh |
CVE-2026-7057Tenda F456 httpd setcfm buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productF456 | Published04/26/2026 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan