Home/Product/tenda w20e firmware
Product

tenda w20e firmware

23 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-24112
all versions
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userI
9.8CRITICAL
CVE-2026-24110
all versions
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long addDhcpRules data. When these rules ente
9.8CRITICAL
CVE-2026-24115
all versions
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of gstup and gstdwn before concatenatin
9.8CRITICAL
CVE-2026-24114
all versions
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate pPortMapIndex may lead to buffer overflows when usi
9.8CRITICAL
CVE-2026-24113
all versions
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr
9.8CRITICAL
CVE-2026-24111
all versions
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userI
9.8CRITICAL
CVE-2026-24109
all versions
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picN
9.8CRITICAL
CVE-2026-24108
all versions
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr
9.8CRITICAL
CVE-2026-24107
all versions
An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of usbPartitionName, which is directly us
9.8CRITICAL
CVE-2025-44867
all versions
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName
6.3MEDIUM
CVE-2025-44866
all versions
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level paramet
6.3MEDIUM
CVE-2025-44865
all versions
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parame
6.3MEDIUM
CVE-2025-44864
all versions
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parame
6.3MEDIUM
CVE-2024-3874
all versions
A vulnerability was found in Tenda W20E 15.11.0.6. It has been declared as critical. This vulnerability affects the function formS
8.8HIGH
CVE-2023-26806
all versions
Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,
9.8CRITICAL
CVE-2023-26805
all versions
Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBind
9.8CRITICAL
CVE-2022-48130
all versions
Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters sta
9.8CRITICAL
CVE-2022-45997
all versions
Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.
7.2HIGH
CVE-2022-45996
all versions
Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
7.2HIGH
CVE-2022-40868
all versions
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the funct
9.8CRITICAL
CVE-2022-40867
all versions
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the funct
9.8CRITICAL
CVE-2022-40866
all versions
Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the funct
9.8CRITICAL
CVE-2022-40855
all versions
Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping
9.8CRITICAL
threatengine.sh