Tenda vulnerabilities
14 CVEs tracked
Tenda appears in our recent reports with multiple critical vulnerabilities across various router models. Key issues include a remotely exploitable `command injection` in the CH22 model (CVE-2026-19346) and numerous `stack-based buffer overflow` flaws in the httpd web management interface of devices like AC1206, G0, W20E, and AC12 (CVE-2026-19788, CVE-2026-19789, CVE-2026-19790, CVE-2026-19791, CVE-2026-19792, CVE-2026-19821, CVE-2026-19822). A critical `hard-coded password` vulnerability in the SSH component (CVE-2026-19750) also poses a high risk for privileged remote access. Defenders should prioritize patching or isolating these devices by restricting access to management interfaces and disabling SSH immediately.
Azərbaycanca: Tenda hesabatlarımızda çoxsaylı ciddi zəifliklərlə diqqət çəkir. Əsasən müxtəlif router modellərində (CH22, AC1206, G0, W20E, AC12) uzaqdan istismar oluna bilən `command injection` (CVE-2026-19346) və çoxsaylı `stack-based buffer overflow` (CVE-2026-19788, CVE-2026-19789, CVE-2026-19790, CVE-2026-19791, CVE-2026-19792, CVE-2026-19821, CVE-2026-19822) zəiflikləri aşkarlanıb. Xüsusilə, CVE-2026-19750 identifikatorlu `hard-coded password` zəifliyi cihazların SSH xidmətinə yüksək imtiyazlı girişi təmin edə bilər. Müdafiəçilər bu vendorun məhsullarını dərhal ən son firmware versiyalarına yeniləməli, mümkün deyilsə, idarəetmə interfeyslərinə girişi ciddi şəkildə məhdudlaşdırmalı (məsələn, yalnız daxili şəbəkədən icazə verməli) və SSH xidmətini deaktiv etməyi nəzərdən keçirməlidir.
This vendor's CVEs14
- CVE-2026-67967EPSS 0.45%
- CVE-2026-67966EPSS 0.41%
- CVE-2026-19924EPSS 0.90%
- CVE-2026-19824EPSS 0.47%
- CVE-2026-19823EPSS 0.47%
- CVE-2026-19822EPSS 0.60%
- CVE-2026-19821EPSS 0.47%
- CVE-2026-19792EPSS 0.47%
- CVE-2026-19791EPSS 0.47%
- CVE-2026-19790EPSS 0.47%
- CVE-2026-19789EPSS 0.47%
- CVE-2026-19788EPSS 0.47%
- CVE-2026-19750EPSS 0.47%
- CVE-2026-19346EPSS 2%
This hub is built from skopnix's own reporting on Tenda: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.