Tenda Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Tenda products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
10
In CISA KEV
3
Beyond CISA KEV
7
Sensor Observed
0
Virtual Patch Available
0
Tenda KEVs Added by Year
10 Tenda KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-7544
Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow |
AC1206 | High | Not in CISA | 15 May 2026 |
|
CVE-2022-40843
The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router... |
AC1200 V-W15Ev2 | High | Not in CISA | 25 Mar 2026 |
|
CVE-2025-7414
Tenda O3V2 httpd setPingInfo fromNetToolGet os command injection |
O3V2 | High | Not in CISA | 10 Jul 2025 |
|
CVE-2018-14558
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through... |
AC7, AC9, AC10 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-10987
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the... |
AC15 AC1900 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-31755
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows... |
AC11 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2024-30891
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters... |
AC18 | High | Not in CISA | 05 Apr 2024 |
|
CVE-2023-27076
Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter. |
G103 | High | Not in CISA | 10 Apr 2023 |
|
CVE-2021-27692
Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute... |
G1 and G3 routers | High | Not in CISA | 15 Apr 2021 |
|
CVE-2020-15916
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell... |
AC15 AC1900 | High | Not in CISA | 23 Jul 2020 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 6
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 2
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 2
- CWE-121 — Stack-based Buffer Overflow 1
- CWE-787 — Out-of-bounds Write 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology