Home/Product/tenda ac18 firmware
Product

tenda ac18 firmware

121 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-31255
all versions
A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg
9.8CRITICAL
CVE-2025-14993
all versions
A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the co
8.8HIGH
CVE-2025-14992
all versions
A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the file /gof
8.8HIGH
CVE-2025-63835
all versions
A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guest
8.8HIGH
CVE-2025-63834
all versions
A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the
5.4MEDIUM
CVE-2025-11328
all versions
A vulnerability was detected in Tenda AC18 15.03.05.19(6318). This issue affects some unknown processing of the file /goform/SetDD
8.8HIGH
CVE-2025-11327
all versions
A security vulnerability has been detected in Tenda AC18 15.03.05.19(6318). This vulnerability affects unknown code of the file /g
8.8HIGH
CVE-2025-11326
all versions
A weakness has been identified in Tenda AC18 15.03.05.19(6318). This affects an unknown part of the file /goform/WifiMacFilterSet.
8.8HIGH
CVE-2025-11325
all versions
A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionality of the f
8.8HIGH
CVE-2025-11324
all versions
A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionality of the
8.8HIGH
CVE-2025-60663
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.
7.5HIGH
CVE-2025-60661
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function
5.3MEDIUM
CVE-2025-60662
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.
7.5HIGH
CVE-2025-60660
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.
7.5HIGH
CVE-2025-11123
all versions
A flaw has been found in Tenda AC18 15.03.05.19. This impacts an unknown function of the file /goform/saveAutoQos. This manipulati
8.8HIGH
CVE-2025-11122
all versions
A vulnerability was detected in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The man
8.8HIGH
CVE-2025-11121
all versions
A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /gof
6.3MEDIUM
CVE-2025-11120
all versions
A weakness has been identified in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the file /gof
8.8HIGH
CVE-2025-9023
all versions
A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file
8.8HIGH
CVE-2025-8182
all versions
A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of
5.6MEDIUM
CVE-2025-5609
all versions
A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function fromadv
8.8HIGH
CVE-2025-5608
all versions
A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formsetreboottimer of th
8.8HIGH
CVE-2025-5607
all versions
A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPUse
8.8HIGH
CVE-2025-5606
all versions
A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function for
6.3MEDIUM
CVE-2025-0528
all versions
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue
7.2HIGH
CVE-2024-57583
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaC
9.8CRITICAL
CVE-2024-57582
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.
9.8CRITICAL
CVE-2024-57581
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function
9.8CRITICAL
CVE-2024-57580
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
9.8CRITICAL
CVE-2024-57579
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientState functi
9.8CRITICAL
CVE-2024-57578
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm function.
8.8HIGH
CVE-2024-57577
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
5.7MEDIUM
CVE-2024-57575
all versions
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set functi
9.8CRITICAL
CVE-2024-10280
all versions
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated
6.5MEDIUM
CVE-2024-41630
all versions
Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the
7.6HIGH
CVE-2024-33181
all versions
Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parameter at ip/
8.8HIGH
CVE-2024-33182
all versions
Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/g
9.8CRITICAL
CVE-2024-33180
all versions
Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/g
9.8CRITICAL
CVE-2024-34974
all versions
Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.
8.2HIGH
CVE-2024-33835
all versions
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.
9.8CRITICAL
CVE-2024-30891
all versions
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmd
8.8HIGH
CVE-2024-28551
all versions
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the ssid parameter of form_fast_setting_wifi_set function.
7.5HIGH
CVE-2024-28545
all versions
Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.
9.8CRITICAL
CVE-2024-2854
all versions
A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetSambaConf of the
6.3MEDIUM
CVE-2024-28547
all versions
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.
6.5MEDIUM
CVE-2024-28537
all versions
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
9.8CRITICAL
CVE-2024-28550
all versions
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.
4.3MEDIUM
CVE-2024-2560
all versions
A vulnerability classified as problematic was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function from
4.3MEDIUM
CVE-2024-2559
all versions
A vulnerability classified as problematic has been found in Tenda AC18 15.03.05.05. Affected is the function fromSysToolReboot of
4.3MEDIUM
CVE-2024-2558
all versions
A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formexeCommand
8.8HIGH
CVE-2024-2547
all versions
A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function R7WebsSecur
8.8HIGH
CVE-2024-2546
all versions
A vulnerability has been found in Tenda AC18 15.13.07.09 and classified as critical. Affected by this vulnerability is the functio
8.8HIGH
CVE-2024-2490
all versions
A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function setSche
8.8HIGH
CVE-2024-2489
all versions
A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetQosBand of the fi
8.8HIGH
CVE-2024-2488
all versions
A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPSer
8.8HIGH
CVE-2024-2487
all versions
A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function for
8.8HIGH
CVE-2024-2486
all versions
A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex
8.8HIGH
CVE-2024-2485
all versions
A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function formSetSpee
8.8HIGH
CVE-2024-28553
all versions
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.
9.8CRITICAL
CVE-2024-28535
all versions
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.
9.8CRITICAL
CVE-2023-38823
all versions
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitr
9.8CRITICAL
CVE-2023-30135
all versions
Tenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the
9.8CRITICAL
CVE-2023-24170
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.
9.8CRITICAL
CVE-2023-24169
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.
9.8CRITICAL
CVE-2023-24167
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node.
9.8CRITICAL
CVE-2023-24166
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.
9.8CRITICAL
CVE-2023-24165
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo.
9.8CRITICAL
CVE-2023-24164
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318.
9.8CRITICAL
CVE-2022-44183
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.
9.8CRITICAL
CVE-2022-44180
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.
9.8CRITICAL
CVE-2022-44178
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.
9.8CRITICAL
CVE-2022-44177
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.
9.8CRITICAL
CVE-2022-44176
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.
9.8CRITICAL
CVE-2022-44175
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
9.8CRITICAL
CVE-2022-44174
all versions
Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.
9.8CRITICAL
CVE-2022-44172
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.
9.8CRITICAL
CVE-2022-44171
all versions
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.
9.8CRITICAL
CVE-2022-43260
all versions
Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.
9.8CRITICAL
CVE-2022-40861
all versions
Tenda AC18 router V15.03.05.19 contains a stack overflow vulnerability in the formSetQosBand-FUN_0007db78 function with the reques
7.2HIGH
CVE-2022-40854
all versions
Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set
9.8CRITICAL
CVE-2022-40869
all versions
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined
9.8CRITICAL
CVE-2022-40865
all versions
Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /gofo
9.8CRITICAL
CVE-2022-40864
all versions
Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the r
9.8CRITICAL
CVE-2022-40862
all versions
Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the reques
9.8CRITICAL
CVE-2022-38326
all versions
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via
9.8CRITICAL
CVE-2022-38325
all versions
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via
9.8CRITICAL
CVE-2022-38314
all versions
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveP
9.8CRITICAL
CVE-2022-38313
all versions
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveP
9.8CRITICAL
CVE-2022-38312
all versions
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIp
9.8CRITICAL
CVE-2022-38311
all versions
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/Power
9.8CRITICAL
CVE-2022-38310
all versions
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetSt
9.8CRITICAL
CVE-2022-38309
all versions
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVi
9.8CRITICAL
CVE-2022-35201
all versions
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
9.8CRITICAL
CVE-2022-31446
all versions
Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac
9.8CRITICAL
CVE-2022-30477
all versions
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when ha
9.8CRITICAL
CVE-2022-30476
all versions
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when ha
9.8CRITICAL
CVE-2022-30475
all versions
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when ha
7.5HIGH
CVE-2022-30474
all versions
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform
9.8CRITICAL
CVE-2022-30473
all versions
Tenda AC Series Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function form_fast_setting_wifi_
7.5HIGH
CVE-2022-30472
all versions
Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat
9.8CRITICAL
CVE-2020-24987
<= v15.03.05.05_en
Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to inc
9.8CRITICAL
CVE-2020-13394
all versions
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC
9.8CRITICAL
CVE-2020-13393
all versions
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC
9.8CRITICAL
CVE-2020-13392
all versions
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC
9.8CRITICAL
CVE-2020-13391
all versions
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC
9.8CRITICAL
CVE-2020-13390
all versions
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC
9.8CRITICAL
CVE-2020-13389
all versions
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC
9.8CRITICAL
CVE-2018-18732
all versions
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
7.5HIGH
CVE-2018-18731
all versions
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
7.5HIGH
CVE-2018-18730
all versions
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
7.5HIGH
CVE-2018-18729
all versions
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
9.8CRITICAL
CVE-2018-18728
all versions
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They all
9.8CRITICAL
CVE-2018-18727
all versions
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
7.5HIGH
CVE-2018-18709
all versions
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
7.5HIGH
CVE-2018-18708
all versions
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
7.5HIGH
CVE-2018-18707
all versions
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
7.5HIGH
CVE-2018-18706
all versions
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
7.5HIGH
CVE-2018-16333
<= 15.03.05.19
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and A
7.5HIGH
CVE-2018-14492
<= 15.03.05.19\(6318\)_cn
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based
7.5HIGH
CVE-2017-16936
all versions
Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03
6.5MEDIUM
CVE-2017-16923
all versions
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.0
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin