Home/Product/tenda ax1803 firmware
Product

tenda ax1803 firmware

60 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-1329
all versions
A flaw has been found in Tenda AX1803 1.0.0.1. The affected element is the function fromGetWifiGuestBasic of the file /goform/Wifi
8.8HIGH
CVE-2025-70648
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function. This vuln
7.5HIGH
CVE-2025-70646
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. This vulnera
7.5HIGH
CVE-2025-70651
all versions
Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_set function
7.5HIGH
CVE-2025-63457
all versions
Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. This vulnera
7.5HIGH
CVE-2025-63456
all versions
Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. This vulne
7.5HIGH
CVE-2025-63458
all versions
Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set fun
7.5HIGH
CVE-2025-7598
all versions
A vulnerability classified as critical was found in Tenda AX1803 1.0.0.1. Affected by this vulnerability is the function formSetWi
8.8HIGH
CVE-2025-7597
all versions
A vulnerability classified as critical has been found in Tenda AX1803 1.0.0.1. Affected is the function formSetMacFilterCfg of the
8.8HIGH
CVE-2024-4236
all versions
A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1. This issue affects the function formSet
8.8HIGH
CVE-2024-30621
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.
9.8CRITICAL
CVE-2024-30620
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.
9.8CRITICAL
CVE-2023-51970
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
9.8CRITICAL
CVE-2023-51969
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.
9.8CRITICAL
CVE-2023-51968
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.
9.8CRITICAL
CVE-2023-51967
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.
9.8CRITICAL
CVE-2023-51962
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.
9.8CRITICAL
CVE-2023-51965
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.
9.8CRITICAL
CVE-2023-51964
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
9.8CRITICAL
CVE-2023-51963
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.
9.8CRITICAL
CVE-2023-51960
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
9.8CRITICAL
CVE-2023-51959
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.
9.8CRITICAL
CVE-2023-51958
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
9.8CRITICAL
CVE-2023-51957
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
9.8CRITICAL
CVE-2023-51956
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv
9.8CRITICAL
CVE-2023-51955
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
9.8CRITICAL
CVE-2023-51954
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.
9.8CRITICAL
CVE-2023-51953
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
9.8CRITICAL
CVE-2023-51952
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
9.8CRITICAL
CVE-2023-51966
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
9.8CRITICAL
CVE-2023-51961
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.
9.8CRITICAL
CVE-2023-51972
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
9.8CRITICAL
CVE-2023-51971
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.
9.8CRITICAL
CVE-2023-49044
all versions
Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter i
9.8CRITICAL
CVE-2023-49047
all versions
Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.
7.5HIGH
CVE-2023-49042
all versions
Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime pa
9.8CRITICAL
CVE-2023-49040
all versions
An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_s
9.8CRITICAL
CVE-2023-49046
all versions
Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName paramete
9.8CRITICAL
CVE-2023-49043
all versions
Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto p
9.8CRITICAL
CVE-2023-48111
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . Th
7.5HIGH
CVE-2023-48110
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the urls parameter in the function saveParentControlInfo . Thi
7.5HIGH
CVE-2023-48109
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentControlInfo .
7.5HIGH
CVE-2022-45781
<= 1.0.0.1_2994
Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /goform/SetOnli
8.8HIGH
CVE-2022-40876
all versions
In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a st
9.8CRITICAL
CVE-2022-40875
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.
7.5HIGH
CVE-2022-40874
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can caus
7.5HIGH
CVE-2022-42087
all versions
Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysTool
6.5MEDIUM
CVE-2022-42086
all versions
Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMod
6.5MEDIUM
CVE-2022-37824
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasi
7.8HIGH
CVE-2022-37823
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSer.
7.8HIGH
CVE-2022-37822
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic.
7.8HIGH
CVE-2022-37821
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in the function formSetProvince.
7.8HIGH
CVE-2022-37820
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysToolDDNS.
7.8HIGH
CVE-2022-37819
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the function fromSetSysTime.
7.8HIGH
CVE-2022-37818
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.
7.8HIGH
CVE-2022-37817
all versions
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetIpMacBind.
7.8HIGH
CVE-2022-34596
all versions
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
9.8CRITICAL
CVE-2022-34595
all versions
Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.
9.8CRITICAL
CVE-2022-30040
all versions
Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bi
7.5HIGH
CVE-2022-28572
all versions
Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in SetIPv6Status function
8.8HIGH
threatengine.sh