VulnSea

Tenda has 38 CVEs on record between 2022 and 2026. Cadence is steady at roughly 12 per quarter. The busiest recent month was September 2026 with 12. The median CVSS is 8.8 (high), with 10 rated critical. 3% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-119 (16) and CWE-121 (13). Most affected products: CP3 (6), cx12l_firmware (5), ac6_firmware (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
3% vs 1% corpus
Median CVSS
8.8
Publish → KEV
—
Last 90 days
12 prev 15

Products

  • CP3 6
  • cx12l_firmware 5
  • ac6_firmware 4
  • ch22_firmware 4
  • HG10 3
  • 4g03_pro_firmware 2
38
Total CVEs
10
Critical
0
CISA KEV
1
Exploited

Tenda vulnerabilities

CVEs affecting Tenda, newest first. Open any entry for full detail, references, and exploit status.

38 CVEsRSS

CVE-2025-9812High· 8.8
1y ago

A vulnerability was determined in Tenda CH22 1.0.0.1

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Executing manipulation of the argument cmdinput can lead to buffer overflow. The attack may be p…

▾ Twilighttenda · ch22_firmwareEPSS 0.66%via NVD
CVE-2025-9791High· 8.8
1y ago

A weakness has been identified in Tenda AC20 16.03.08.05

A weakness has been identified in Tenda AC20 16.03.08.05. This vulnerability affects unknown code of the file /goform/fromAdvSetMacMtuWan. This manipulation of the argument wanMTU causes stack-based buffer overflow. Remote exploitation o…

▾ Twilighttenda · ac20_firmwareEPSS 0.85%via NVD
CVE-2025-57220Medium· 5.3
1y ago

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet.

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet.

▾ Sunlittenda · ac10_firmwareEPSS 0.80%via NVD
CVE-2025-57218Medium· 5.3
1y ago

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sub_46284C.

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function sub_46284C.

▾ Sunlittenda · ac10_firmwareEPSS 0.59%via NVD
CVE-2025-52054Medium· 5.3
1y ago

An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05

An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device.…

▾ Sunlittenda · ac8_firmwareEPSS 0.32%via NVD
CVE-2022-35201Critical· 9.8
4y ago

Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.

Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.

▾ Midnighttenda · ac18_firmwareEPSS 3.5%via NVD
CVE-2022-30023High· 8.8⚠ ExploitedPoC
4y ago

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

▾ Midnighttenda · hg9_firmwareEPSS 39%via NVD
CVE-2021-44971Critical· 9.8
4y ago

Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on

Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticate…

▾ Midnighttenda · ac15_firmwareEPSS 2.1%via NVD
Tenda vulnerabilities (CVEs) — page 2 · VulnSea