AC15
Tenda- Software type
- —
- Catalog vulnerabilities
- 36
Severity across 36 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 36 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 36 vulnerability records affecting AC15.
Among the 36 records analyzed by CyStack, 31 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-11493Tenda AC15 Samba smb.conf weak password | Exploitation statusPublic exploit | FixNot confirmed | Published06/08/2026 | SeverityLow |
CVE-2026-4975Tenda AC15 POST Request setcfm formSetCfm memory corruption | Exploitation statusPublic exploit | FixNot confirmed | Published03/27/2026 | SeverityHigh |
CVE-2026-3400Tenda AC15 TextEditingConversion stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/01/2026 | SeverityHigh |
CVE-2025-11389Tenda AC15 saveAutoQos stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/07/2025 | SeverityHigh |
CVE-2025-11388Tenda AC15 setNotUpgrade stack-based overflow | Exploitation statusPublic exploit | FixYes | Published10/07/2025 | SeverityHigh |
CVE-2025-11387Tenda AC15 fast_setting_pppoe_set stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/07/2025 | SeverityHigh |
CVE-2025-11386Tenda AC15 POST Parameter SetDDNSCfg stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/07/2025 | SeverityHigh |
CVE-2025-10443Tenda AC9/AC15 exeCommand formexeCommand buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/15/2025 | SeverityHigh |
CVE-2025-10442Tenda AC9/AC15 exeCommand formexeCommand os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/15/2025 | SeverityMedium |
CVE-2025-8979Tenda AC15 Firmware Update check_fw data authenticity | Exploitation statusPublic exploit | FixYes | Published08/14/2025 | SeverityHigh |
CVE-2025-5851Tenda AC15 HTTP POST Request AdvSetLanip fromadvsetlanip buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/08/2025 | SeverityHigh |
CVE-2025-5850Tenda AC15 HTTP POST Request SetLEDCf formsetschedled buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/08/2025 | SeverityHigh |
CVE-2025-5849Tenda AC15 HTTP POST Request SetRemoteWebCfg formSetSafeWanWebMan stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/08/2025 | SeverityHigh |
CVE-2025-5848Tenda AC15 HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/08/2025 | SeverityHigh |
CVE-2025-3786Tenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/18/2025 | SeverityHigh |
CVE-2025-0566Tenda AC15 SetDevNetName formSetDevNetName stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published01/19/2025 | SeverityHigh |
CVE-2024-10662Tenda AC15 SetOnlineDevName formSetDeviceName stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published11/01/2024 | SeverityHigh |
CVE-2024-10661Tenda AC15 SetDlnaCfg stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published11/01/2024 | SeverityHigh |
CVE-2024-10280Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference | Exploitation statusPublic exploit | FixNot confirmed | Published10/23/2024 | SeverityHigh |
CVE-2024-2855Tenda AC15 SetSysTimeCfg fromSetSysTime stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/24/2024 | SeverityHigh |
CVE-2024-2852Tenda AC15 saveParentControlInfo stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/24/2024 | SeverityHigh |
CVE-2024-2851Tenda AC15 setsambacfg formSetSambaConf os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published03/24/2024 | SeverityMedium |
CVE-2024-2850Tenda AC15 saveParentControlInfo stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/24/2024 | SeverityHigh |
CVE-2024-2817Tenda AC15 SysToolRestoreSet fromSysToolRestoreSet cross-site request forgery | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityMedium |
CVE-2024-2816Tenda AC15 SysToolReboot fromSysToolReboot cross-site request forgery | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityMedium |
CVE-2024-2815Tenda AC15 Cookie execCommand R7WebsSecurityHandler stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CVE-2024-2814Tenda AC15 DhcpListClient fromDhcpListClient stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CVE-2024-2813Tenda AC15 fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CVE-2024-2812Tenda AC15 WriteFacMac formWriteFacMac os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityMedium |
CVE-2024-2811Tenda AC15 WifiWpsStart formWifiWpsStart stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CVE-2024-2810Tenda AC15 WifiWpsOOB formWifiWpsOOB stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CVE-2024-2809Tenda AC15 SetFirewallCfg formSetFirewallCfg stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CVE-2024-2808Tenda AC15 QuickIndex formQuickIndex stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CVE-2024-2807Tenda AC15 expandDlnaFile formExpandDlnaFile stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CVE-2024-2806Tenda AC15 addWifiMacFilter stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CVE-2024-2805Tenda AC15 SetSpeedWan formSetSpeedWan stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/22/2024 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan