#Tenda
All CosmicBytez Labs articles tagged #Tenda, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-86148: Tenda CP3 OS Command Injection via AlarmVoiceURL
A critical unauthenticated OS command injection flaw in Tenda CP3 Wi-Fi cameras lets remote attackers run arbitrary commands via the AlarmVoiceURL parameter.
- Security
CVE-2026-86149: Tenda CP3 OS Command Injection via NetCheckPing
A second critical command injection flaw in Tenda CP3 cameras lets remote attackers execute OS commands through the ping utility's host/interface argument.
- Security
CVE-2026-86152: Max-Severity Tenda CP3 Command Injection via AutoAddWifi
CVSS 10.0 flaw in Tenda CP3's Kylin AutoAddWifi thread lets remote attackers inject and execute arbitrary OS commands.
- Security
CVE-2026-86151: Tenda CP3 OS Command Injection via Network Config Handler
Tenda CP3 firmware 27.5.57.101 lets remote attackers inject OS commands through its network configuration handler, no authentication noted.
- Security
CVE-2026-86153: Tenda CP3 Improper Privilege Management in Redirect Service
Tenda CP3's SetRedirectEnable function lacks authorization checks, letting remote attackers alter port-forwarding without admin access.
- Security
Tenda HG10 Routers Hit By Critical Unauthenticated Buffer Overflow
A critical buffer overflow in Tenda HG10 firmware's formURL function allows remote memory corruption with a public exploit and no patch yet.
- Security
Tenda HG10 formgponConf Flaw Allows Unauthenticated Root Command Injection
A near-maximum-severity OS command injection in Tenda HG10's formgponConf function lets attackers run root commands remotely; no patch is available.
- Security
CVE-2026-38577: Tenda HG21 Hardcoded Admin Credentials
Hardcoded admin credentials baked into Tenda HG21 firmware let attackers bypass authentication and gain full root access to the router.
- Security
Critical Unauthenticated Buffer Overflow in Tenda HG10 Routers
CVE-2026-82542 (CVSS 10) lets remote attackers trigger a buffer overflow in Tenda HG10 routers via the formIPv6Routing handler. Public exploit exists.
- Security
CVE-2024-51311: Critical Stack Overflow in Tenda TX9 Router Firmware
A critical stack overflow vulnerability (CVSS 9.8) in Tenda TX9 firmware V22.03.02.05 allows remote attackers to execute arbitrary code via a crafted...
- Security
CVE-2026-51380: Tenda AC10 v3 Buffer Overflow Enables DoS and Remote Code Execution
A critical CVSS 9.8 buffer overflow vulnerability in Tenda AC10 v3 firmware V03.03.16.09 allows remote attackers to cause permanent denial of service or...
- Security
Tenda A15 UploadCfg Stack Buffer Overflow (CVE-2026-4567)
A CVSS 9.8 Critical stack-based buffer overflow in Tenda A15 firmware 15.13.07.13 allows unauthenticated remote attackers to execute arbitrary code by...