VulnSea

tenda has 31 CVEs on record between 2022 and 2026. Cadence is steady at roughly 12 per quarter. The busiest recent month was September 2026 with 12. The median CVSS is 8.8 (high), with 10 rated critical. 3% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-119 (13) and CWE-121 (10). Most affected products: CP3 (6), cx12l_firmware (5), ac6_firmware (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
3% vs 1% corpus
Median CVSS
8.8
Publish → KEV
Last 90 days
12 prev 16

Products

  • CP3 6
  • cx12l_firmware 5
  • ac6_firmware 4
  • HG10 3
  • 4g03_pro_firmware 2
  • W20E 2
31
Total CVEs
10
Critical
0
CISA KEV
1
Exploited

tenda vulnerabilities

CVEs affecting tenda, newest first. Open any entry for full detail, references, and exploit status.

31 CVEsRSS

CVE-2026-90688Medium· 6.5PoC
1w ago

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overf…

TwilightTenda · W20EEPSS 0.40%via NVD
CVE-2026-90689High· 8.8
1w ago

A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC

A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. Th…

TwilightTenda · W20EEPSS 0.60%via NVD
CVE-2026-86300High· 7.3PoC
2w ago

A flaw has been found in Tenda AC9 15.03.05.14

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be initiated remotely. The exploit has been…

MidnightTenda · AC9EPSS 0.49%via NVD
CVE-2026-86167Critical· 9.9PoC
2w ago

A vulnerability was identified in Tenda HG10 300001138

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remot…

AbyssalTenda · HG10EPSS 1.6%via NVD
CVE-2026-86166High· 8.8PoC
2w ago

A vulnerability was determined in Tenda HG10 300001138

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer …

MidnightTenda · HG10EPSS 0.48%via NVD
CVE-2026-86165Critical· 9.8PoC
2w ago

A vulnerability was found in Tenda HG10 300001138

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be …

AbyssalTenda · HG10EPSS 0.64%via NVD
CVE-2026-86153Critical· 9.1
2w ago

A vulnerability has been found in Tenda CP3 27.5.57.101

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the at…

MidnightTenda · CP3EPSS 0.39%via NVD
CVE-2026-86152Critical· 10.0
2w ago

A flaw has been found in Tenda CP3 27.5.57.101

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The at…

MidnightTenda · CP3EPSS 1.9%via NVD
CVE-2026-86151Critical· 9.1PoC
2w ago

A vulnerability was detected in Tenda CP3 27.5.57.101

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection…

AbyssalTenda · CP3EPSS 2.0%via NVD
CVE-2026-86150Medium· 4.1
2w ago

A security vulnerability has been detected in Tenda CP3 27.5.57.101

A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be…

SunlitTenda · CP3EPSS 0.22%via NVD
CVE-2026-86149Critical· 9.1
2w ago

A weakness has been identified in Tenda CP3 27.5.57.101

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be in…

MidnightTenda · CP3EPSS 2.0%via NVD
CVE-2026-86148Critical· 9.1
2w ago

A security flaw has been discovered in Tenda CP3 27.5.57.101

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command inject…

MidnightTenda · CP3EPSS 2.5%via NVD
CVE-2026-8265Medium· 4.7
4mo ago

A security vulnerability has been detected in Tenda AC6 15.03.06.23

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os comman…

Sunlittenda · ac6_firmwareEPSS 4.4%via NVD
CVE-2026-8264Medium· 6.3
4mo ago

A weakness has been identified in Tenda AC6 15.03.06.23

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl…

Sunlittenda · ac6_firmwareEPSS 2.9%via NVD
CVE-2026-8263Medium· 4.7
4mo ago

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results …

Sunlittenda · ac10u_firmwareEPSS 4.6%via NVD
CVE-2026-8259Medium· 4.7
4mo ago

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exp…

Sunlittenda · ac6_firmwareEPSS 4.4%via NVD
CVE-2025-52221Critical· 9.8
5mo ago

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.

Midnighttenda · ac6_firmwareEPSS 0.39%via NVD
CVE-2026-5687High· 8.8
5mo ago

A weakness has been identified in Tenda CX12L 16.03.53.12

A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. This manipulation of the argument page causes stack-based buffer overflow. The attack m…

Twilighttenda · cx12l_firmwareEPSS 0.67%via NVD
CVE-2026-5686High· 8.8
5mo ago

A security flaw has been discovered in Tenda CX12L 16.03.53.12

A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page results in stack-based buffer overflow. The at…

Twilighttenda · cx12l_firmwareEPSS 0.67%via NVD
CVE-2026-5685High· 8.8
5mo ago

A vulnerability was identified in Tenda CX12L 16.03.53.12

A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated r…

Twilighttenda · cx12l_firmwareEPSS 0.69%via NVD
CVE-2026-5684High· 8.0
5mo ago

A vulnerability was determined in Tenda CX12L 16.03.53.12

A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to stack-based bu…

Twilighttenda · cx12l_firmwareEPSS 0.62%via NVD
CVE-2026-5683Medium· 5.5
5mo ago

A vulnerability was found in Tenda CX12L 16.03.53.12

A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. Performing a manipulation of the argument page results in stack-based buffer overfl…

Sunlittenda · cx12l_firmwareEPSS 0.62%via NVD
CVE-2026-5609High· 8.8
5mo ago

A flaw has been found in Tenda i12 1.0.0.11(3862)

A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component Parameter Handler. This manipulation of the argument index/wl_radio causes …

Twilighttenda · i12_firmwareEPSS 0.63%via NVD
CVE-2026-5605High· 8.8
5mo ago

A weakness has been identified in Tenda CH22 1.0.0.1

A weakness has been identified in Tenda CH22 1.0.0.1. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack can be execu…

Twilighttenda · ch22_firmwareEPSS 0.69%via NVD
CVE-2026-5567High· 8.8
5mo ago

A flaw has been found in Tenda M3 1.0.0.10

A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead …

Twilighttenda · m3_firmwareEPSS 0.63%via NVD
CVE-2026-5527Medium· 5.3
5mo ago

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation c…

Sunlittenda · 4g03_pro_firmwareEPSS 0.43%via NVD
CVE-2026-5526High· 7.3
5mo ago

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The att…

Twilighttenda · 4g03_pro_firmwareEPSS 0.36%via NVD
CVE-2026-5204High· 8.8
5mo ago

A vulnerability was determined in Tenda CH22 1.0.0.1

A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffe…

Twilighttenda · ch22_firmwareEPSS 2.5%via NVD
CVE-2022-35201Critical· 9.8
4y ago

Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.

Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.

Midnighttenda · ac18_firmwareEPSS 3.5%via NVD
CVE-2022-30023High· 8.8⚠ ExploitedPoC
4y ago

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

Midnighttenda · hg9_firmwareEPSS 39%via NVD
tenda vulnerabilities (CVEs) · VulnSea