Tenda vendor intelligence

Tenda Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Tenda products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Tenda KEVs Full KEV feed
Total KEVs
10
Known exploited vulnerabilities affecting Tenda products
In CISA KEV
3
Records also listed in the official catalog
Beyond CISA KEV
7
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Tenda KEVs with sensor-observed exploitation activity

The catalog gap matters for Tenda exposure

Seven of the ten exploited Tenda CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 70% of this vendor portfolio.

30%
Covered by CISA
70%
Beyond CISA
9
Product families

Attested Tenda CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2025-7544

Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow

AC1206 High Beyond CISA 15 May 2026
CVE-2022-40843

The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router...

AC1200 V-W15Ev2 High Beyond CISA 25 Mar 2026
CVE-2025-7414

Tenda O3V2 httpd setPingInfo fromNetToolGet os command injection

O3V2 High Beyond CISA 10 Jul 2025
CVE-2018-14558

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through...

AC7, AC9, AC10 Confirmed In CISA 03 Nov 2021
CVE-2020-10987

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the...

AC15 AC1900 Confirmed In CISA 03 Nov 2021
CVE-2021-31755

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows...

AC11 Confirmed In CISA 03 Nov 2021
CVE-2024-30891

A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters...

AC18 High Beyond CISA 05 Apr 2024
CVE-2023-27076

Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.

G103 High Beyond CISA 10 Apr 2023
CVE-2021-27692

Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute...

G1 and G3 routers High Beyond CISA 15 Apr 2021
CVE-2020-15916

goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell...

AC15 AC1900 High Beyond CISA 23 Jul 2020

Showing 10 of 10 Tenda known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, restriction, and neutralization account for ten mapped occurrences across this Tenda KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.