Tenda Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Tenda products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

10

In CISA KEV

3

Beyond CISA KEV

7

Sensor Observed

0

Virtual Patch Available

0

Tenda KEVs Added by Year

Loading...

10 Tenda KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-7544

Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow

High Not in CISA 15 May 2026
CVE-2022-40843

The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router...

High Not in CISA 25 Mar 2026
CVE-2025-7414

Tenda O3V2 httpd setPingInfo fromNetToolGet os command injection

High Not in CISA 10 Jul 2025
CVE-2018-14558

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through...

Confirmed In CISA 03 Nov 2021
CVE-2020-10987

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the...

Confirmed In CISA 03 Nov 2021
CVE-2021-31755

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows...

Confirmed In CISA 03 Nov 2021
CVE-2024-30891

A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters...

High Not in CISA 05 Apr 2024
CVE-2023-27076

Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.

High Not in CISA 10 Apr 2023
CVE-2021-27692

Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute...

High Not in CISA 15 Apr 2021
CVE-2020-15916

goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell...

High Not in CISA 23 Jul 2020

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 6
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 2
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 2
  • CWE-121 — Stack-based Buffer Overflow 1
  • CWE-787 — Out-of-bounds Write 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology