Tenda Vulnerabilities
Comprehensive security vulnerability database for Tenda products
34
1
34
5
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-3811 | 7.4 | An attacker can remotely exploit a vulnerability in Tenda FH1202 routers to execute arbitrary code by sending specially crafted data to a specific function, which can lead to a crash or unauthorized control of the device. This attack requires no physical access and can be carried out over the internet, making it a significant risk for users with this firmware version. | tendafh1202 firmware | Exploit Available | 29 days agoMar 9, 2026 |
| CVE-2026-3810 | 7.4 | This vulnerability allows an attacker to remotely take control of the Tenda FH1202 router by exploiting a flaw in its DHCP client list function, which can lead to a crash or unauthorized access to the device. The attacker needs to send specially crafted data to the router, making it possible for them to execute harmful code on the device. | tendafh1202 firmware | Exploit Available | 30 days agoMar 9, 2026 |
| CVE-2026-3809 | 7.4 | An attacker can remotely exploit a flaw in the Tenda FH1202 router's firmware to execute arbitrary code by manipulating a specific setting, potentially taking control of the device. This vulnerability requires no special access, making it easy for attackers to target affected routers over the internet. | tendafh1202 firmware | Exploit Available | 30 days agoMar 9, 2026 |
| CVE-2026-3808 | 7.4 | This vulnerability allows an attacker to remotely execute malicious code on the Tenda FH1202 router by exploiting a flaw in how the device handles certain input data. The attacker needs to manipulate a specific argument in the router's web interface, which could lead to unauthorized access or control of the device. | tendafh1202 firmware | Exploit Available | 30 days agoMar 9, 2026 |
| CVE-2026-3807 | 7.4 | An attacker can remotely exploit a vulnerability in the Tenda FH1202 router to execute arbitrary code by sending specially crafted data that causes a buffer overflow, potentially taking control of the device. This attack can happen without needing physical access, making it a serious risk for users of this router firmware version. | tendafh1202 firmware | Exploit Available | 30 days agoMar 9, 2026 |
| CVE-2026-3732 | 7.4 | An attacker can remotely exploit a vulnerability in the Tenda F453 router to execute arbitrary code by sending specially crafted commands, which can lead to full control over the device. This requires the attacker to know the specific command format to trigger a buffer overflow in the router's firmware. | tendaf453 firmware | Exploit Available | about 1 month agoMar 8, 2026 |
| CVE-2026-3729 | 7.4 | An attacker can remotely take control of the Tenda F453 router by exploiting a flaw in its firmware that allows them to overflow a memory area, potentially leading to unauthorized access or execution of malicious code. This vulnerability can be triggered by manipulating specific input fields, making it easy for attackers to exploit if they know how to send the right data. | tendaf453 firmware | Exploit Available | about 1 month agoMar 8, 2026 |
| CVE-2026-3728 | 7.4 | An attacker can remotely exploit a vulnerability in the Tenda F453 router to execute arbitrary code by causing a stack-based buffer overflow through a specific function in its firmware. This means that if the attacker knows how to manipulate certain inputs, they can gain control over the router and potentially compromise the network it’s connected to. | tendaf453 firmware | Exploit Available | about 1 month agoMar 8, 2026 |
| CVE-2026-3727 | 7.4 | This vulnerability allows an attacker to remotely execute malicious code on the Tenda F453 router by exploiting a flaw in the firmware that leads to a stack-based buffer overflow. The attacker needs to manipulate specific input fields, which means they can potentially take control of the device without needing physical access. | tendaf453 firmware | Exploit Available | about 1 month agoMar 8, 2026 |
| CVE-2026-3726 | 7.4 | An attacker can remotely exploit a vulnerability in the Tenda F453 router to execute arbitrary code by sending specially crafted data that causes a buffer overflow. This requires no special access, making it easy for attackers to take control of the device if it is connected to the internet. | tendaf453 firmware | Exploit Available | about 1 month agoMar 8, 2026 |
| CVE-2025-69765 | 7.5 | This vulnerability allows an attacker to run their own malicious code on the Tenda AX3 router remotely, potentially taking full control of the device. To exploit this, the attacker needs to send a specially crafted request to the router's firmware, which can lead to serious security risks for the network it manages. | tendaax3 firmware | Theoretical | about 1 month agoMar 3, 2026 |
| CVE-2026-3400 | 7.4 | An attacker can remotely exploit a vulnerability in the Tenda AC15 router to execute arbitrary code by manipulating a specific setting, which can lead to a complete takeover of the device. This attack can be carried out without any special access requirements, making it particularly dangerous for users who haven't updated their firmware. | tendaac15 firmware | Exploit Available | about 1 month agoMar 2, 2026 |
| CVE-2026-3399 | 7.4 | An attacker can remotely exploit a vulnerability in the Tenda F453 router to execute arbitrary code by manipulating a specific input, which can lead to a complete system compromise. This attack requires no special access, making it particularly dangerous since the exploit is publicly available. | tendaf453 firmware | Exploit Available | about 1 month agoMar 1, 2026 |
| CVE-2026-3398 | 7.4 | This vulnerability allows an attacker to remotely crash the Tenda F453 router or potentially take control of it by exploiting a flaw in how it handles certain settings. The attacker needs to manipulate specific input related to the router's WAN settings, which could lead to a serious security breach. | tendaf453 firmware | Exploit Available | about 1 month agoMar 1, 2026 |
| CVE-2026-3380 | 7.4 | An attacker can remotely exploit a vulnerability in the Tenda F453 router to execute arbitrary code by manipulating a specific input, which can lead to a complete takeover of the device. This requires no special access, making it a serious risk for anyone using this firmware version. | tendaf453 firmware | Exploit Available | about 1 month agoMar 1, 2026 |
| CVE-2026-3379 | 7.4 | An attacker can remotely exploit a vulnerability in the Tenda F453 router to execute malicious code by manipulating a specific function, which can lead to a crash or unauthorized access to the device. This requires the attacker to send specially crafted requests to the router's firmware without needing physical access. | tendaf453 firmware | Exploit Available | about 1 month agoMar 1, 2026 |
| CVE-2026-3378 | 7.4 | An attacker can remotely exploit a flaw in the Tenda F453 router's firmware to cause a buffer overflow, potentially allowing them to take control of the device. This vulnerability requires the attacker to manipulate specific settings related to quality of service (QoS) in the router's configuration. | tendaf453 firmware | Exploit Available | about 1 month agoMar 1, 2026 |
| CVE-2026-3377 | 7.4 | This vulnerability allows an attacker to remotely execute malicious code on the Tenda F453 router by exploiting a flaw in the way it handles certain input, which can lead to a buffer overflow. To be successful, the attacker needs to manipulate specific data sent to the router's SafeUrlFilter function. | tendaf453 firmware | Exploit Available | about 1 month agoMar 1, 2026 |
| CVE-2026-3376 | 7.4 | This vulnerability allows an attacker to remotely execute malicious code on the Tenda F453 router by exploiting a flaw in the way it handles certain input, leading to a buffer overflow. The attacker can take advantage of this issue without needing physical access to the device, making it a serious risk for users. | tendaf453 firmware | Exploit Available | about 1 month agoFeb 28, 2026 |
| CVE-2026-3169 | 7.4 | This vulnerability allows an attacker to remotely take control of the Tenda F453 router by exploiting a flaw in its email filtering function, which can lead to a buffer overflow. The attacker needs to send specially crafted requests to the router, making it possible for them to execute malicious code. | tendaf453 firmware | Exploit Available | about 1 month agoFeb 25, 2026 |
About Tenda Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Tenda products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.