📦

ax1806

Vendor: tenda

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 18 Remote Access
Total CVEs 72 Total Indexed
Avg. EPSS 1.30% Exploit Prob.
Latest CVE CVE-2025-70644 Jan 21

Security Vulnerability Index

Page 5 / 8
7.5 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetRouteStatic.

EPSS: 1.10%
7.5 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetQosBand.

EPSS: 1.10%
7.5 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the function fromAdvSetMacMtuWan. This vulnerability allows attackers to cause a Denial of Service (DoS).

EPSS: 1.16%
7.5 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS).

EPSS: 1.16%
7.5 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetIpMacBind. This vulnerability allows attackers to cause a Denial of Service (DoS).

EPSS: 1.16%
7.5 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS).

EPSS: 1.16%
7.5 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS).

EPSS: 1.16%
8.8 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function

EPSS: 2.66%
7.5 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

EPSS: 1.24%
7.5 CVSS

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetProvince. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ProvinceCode parameter.

EPSS: 1.24%