Tenda W6-S是中国腾达(Tenda)公司的一个无线接入点设备。 Tenda W6-S 1.0.0.4版本存在操作系统命令注入漏洞,该漏洞源于对组件ATE Service中文件/goform/ate的错误操作,可能导致os命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-15255 | 9.8 CRITICAL | Tenda W6-S R7websSsecurityHandler httpd stack-based overflow |
| CVE-2025-15215 | 8.8 HIGH | Tenda AC10U HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflow |
| CVE-2025-15216 | 8.8 HIGH | Tenda AC23 SetIpMacBind fromSetIpMacBind stack-based overflow |
| CVE-2025-15217 | 8.8 HIGH | Tenda AC23 HTTP POST Request formSetPPTPUserList buffer overflow |
| CVE-2025-15218 | 8.8 HIGH | Tenda AC10U POST Request Parameter AdvSetLanip fromadvsetlanip buffer overflow |
| CVE-2025-15230 | 8.8 HIGH | Tenda M3 setVlanPolicyData formSetVlanPolicy heap-based overflow |
| CVE-2025-15231 | 8.8 HIGH | Tenda M3 setVlanInfo formSetRemoteVlanInfo stack-based overflow |
| CVE-2025-15232 | 8.8 HIGH | Tenda M3 setAdPushInfo formSetAdPushInfo stack-based overflow |
| CVE-2025-15233 | 8.8 HIGH | Tenda M3 setAdInfoDetail formSetAdInfoDetails heap-based overflow |
| CVE-2025-15234 | 8.8 HIGH | Tenda M3 setInternetLanInfo formSetRemoteInternetLanInfo heap-based overflow |
| CVE-2025-15252 | 8.8 HIGH | Tenda M3 setDhcpAP formSetRemoteDhcpForAp stack-based overflow |
| CVE-2025-15253 | 8.8 HIGH | Tenda M3 exeCommand stack-based overflow |
| CVE-2025-15356 | 8.8 HIGH | Tenda AC20 PowerSaveSet sscanf buffer overflow |
| CVE-2025-15229 | 5.3 MEDIUM | Tenda CH22 DhcpListClient fromDhcpListClient denial of service |
No comments yet