AC9
Tenda- Software type
- —
- Catalog vulnerabilities
- 14
Severity across 14 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 14 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 14 vulnerability records affecting AC9.
Among the 14 records analyzed by CyStack, 8 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-86300Tenda AC9 Web Management R7WebsSecurityHandler improper authentication | Exploitation statusPublic exploit | FixNot confirmed | Published09/07/2026 | SeverityMedium |
CVE-2026-6016Tenda AC9 POST Request WizardHandle decodePwd stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/10/2026 | SeverityHigh |
CVE-2026-6015Tenda AC9 POST Request QuickIndex formQuickIndex stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/10/2026 | SeverityHigh |
CVE-2026-2192Tenda AC9 formGetRebootTimer stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published02/08/2026 | SeverityHigh |
CVE-2026-2191Tenda AC9 formGetDdosDefenceList stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published02/08/2026 | SeverityHigh |
CVE-2025-14286Tenda AC9 Configuration File DownloadCfg.jpg information disclosure | Exploitation statusPublic exploit | FixNot confirmed | Published12/09/2025 | SeverityMedium |
CVE-2025-10443Tenda AC9/AC15 exeCommand formexeCommand buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published09/15/2025 | SeverityHigh |
CVE-2025-10442Tenda AC9/AC15 exeCommand formexeCommand os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published09/15/2025 | SeverityMedium |
CVE-2025-9731Tenda AC9 Administrative shadow hard-coded credentials | Exploitation statusPublic exploit | FixNot confirmed | Published08/31/2025 | SeverityLow |
CVE-2025-5900Tenda AC9 cross-site request forgery | Exploitation statusPublic exploit | FixNot confirmed | Published06/09/2025 | SeverityMedium |
CVE-2025-5847Tenda AC9 HTTP POST Request SetRemoteWebCfg formSetSafeWanWebMan stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/08/2025 | SeverityHigh |
CVE-2025-5839Tenda AC9 POST Request AdvSetLanip fromadvsetlanip buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/07/2025 | SeverityHigh |
CVE-2025-5836Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection | Exploitation statusPublic exploit | FixNot confirmed | Published06/07/2025 | SeverityMedium |
CVE-2024-10280Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference | Exploitation statusPublic exploit | FixNot confirmed | Published10/23/2024 | SeverityHigh |