CVE-2021-44971Critical· 9.8▾ MidnightMultiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticate…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.6%
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
ac15_firmware = 15.03.05.20_multiac5_firmware = 15.03.06.48_multiRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-30023High· 8.8Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
CVE-2026-90688Medium· 6.5A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC
CVE-2026-90689High· 8.8A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC
CVE-2026-86300High· 7.3A flaw has been found in Tenda AC9 15.03.05.14
CVE-2026-86167Critical· 9.9A vulnerability was identified in Tenda HG10 300001138
CVE-2026-86166High· 8.8A vulnerability was determined in Tenda HG10 300001138