AC18
Tenda- Software type
- —
- Catalog vulnerabilities
- 32
Severity across 32 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 32 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, AC18 has 1 security vulnerability published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of AC18 and determine which vulnerabilities affect that version.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-82695Tenda AC18 Telnet telnet missing authentication | Exploitation statusPublic exploit | FixNot confirmed | Published08/31/2026 | SeverityCritical |
CVE-2026-11528Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/08/2026 | SeverityHigh |
CVE-2025-14993Tenda AC18 HTTP Request SetDlnaCfg sprintf stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published12/21/2025 | SeverityHigh |
CVE-2025-14992Tenda AC18 HTTP Request GetParentControlInfo strcpy stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published12/21/2025 | SeverityHigh |
CVE-2025-11328Tenda AC18 SetDDNSCfg stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/06/2025 | SeverityHigh |
CVE-2025-11327Tenda AC18 SetUpnpCfg stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/06/2025 | SeverityHigh |
CVE-2025-11326Tenda AC18 WifiMacFilterSet stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/06/2025 | SeverityHigh |
CVE-2025-11325Tenda AC18 fast_setting_pppoe_set stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/06/2025 | SeverityHigh |
CVE-2025-11324Tenda AC18 setNotUpgrade stack-based overflow | Exploitation statusPublic exploit | FixYes | Published10/06/2025 | SeverityHigh |
CVE-2025-11123Tenda AC18 saveAutoQos stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/28/2025 | SeverityHigh |
CVE-2025-11122Tenda AC18 WizardHandle stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/28/2025 | SeverityHigh |
CVE-2025-11121Tenda AC18 AdvSetLanip command injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/28/2025 | SeverityMedium |
CVE-2025-9023Tenda AC7/AC18 SetLEDCfg formSetSchedLed buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published08/15/2025 | SeverityHigh |
CVE-2025-8182Tenda AC18 Samba smb.conf weak password | Exploitation statusPublic exploit | FixNot confirmed | Published07/26/2025 | SeverityMedium |
CVE-2025-5609Tenda AC18 AdvSetLanip fromadvsetlanip buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/04/2025 | SeverityHigh |
CVE-2025-5608Tenda AC18 SetSysAutoRebbotCfg formsetreboottimer buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/04/2025 | SeverityHigh |
CVE-2025-5607Tenda AC18 setPptpUserList formSetPPTPUserList buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/04/2025 | SeverityHigh |
CVE-2025-5606Tenda AC18 SetIPTVCfg formSetIptv command injection | Exploitation statusPublic exploit | FixNot confirmed | Published06/04/2025 | SeverityMedium |
CVE-2025-0528Tenda AC8/AC10/AC18 HTTP Request telnet command injection | Exploitation statusPublic exploit | FixNot confirmed | Published01/17/2025 | SeverityHigh |
CVE-2024-10280Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference | Exploitation statusPublic exploit | FixNot confirmed | Published10/23/2024 | SeverityHigh |
CVE-2024-2854Tenda AC18 setsambacfg formSetSambaConf os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published03/24/2024 | SeverityMedium |
CVE-2024-2560Tenda AC18 SysToolRestoreSet fromSysToolRestoreSet cross-site request forgery | Exploitation statusPublic exploit | FixNot confirmed | Published03/17/2024 | SeverityMedium |
CVE-2024-2559Tenda AC18 SysToolReboot fromSysToolReboot cross-site request forgery | Exploitation statusPublic exploit | FixNot confirmed | Published03/17/2024 | SeverityMedium |
CVE-2024-2558Tenda AC18 execCommand formexeCommand stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/17/2024 | SeverityHigh |
CVE-2024-2547Tenda AC18 R7WebsSecurityHandler stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/17/2024 | SeverityHigh |
CVE-2024-2546Tenda AC18 fromSetWirelessRepeat stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/17/2024 | SeverityHigh |
CVE-2024-2490Tenda AC18 openSchedWifi setSchedWifi stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/15/2024 | SeverityHigh |
CVE-2024-2489Tenda AC18 SetNetControlList formSetQosBand stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/15/2024 | SeverityHigh |
CVE-2024-2488Tenda AC18 SetPptpServerCfg formSetPPTPServer stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/15/2024 | SeverityHigh |
CVE-2024-2487Tenda AC18 SetOnlineDevName formSetDeviceName stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/15/2024 | SeverityHigh |
CVE-2024-2486Tenda AC18 QuickIndex formQuickIndex stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/15/2024 | SeverityHigh |
CVE-2024-2485Tenda AC18 SetSpeedWan formSetSpeedWan stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/15/2024 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan