Tenda Vulnerabilities
Shenzhen Tenda Technology makes consumer and small business networking devices, mainly Wi-Fi routers, plus IP cameras and NVRs. The database tracks 15 Tenda CVE records. CISA lists 3 of them as exploited in the wild, most recently on 2021-11-03. The most affected products are AC6, F453, G103.
Recently Exploited Tenda CVEs
Tenda AC11 Router Stack Buffer Overflow Vulnerability
Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
Affected Products
10 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| AC6 | 4 | - | 2026-05-11 |
| F453 | 2 | - | 2026-04-25 |
| G103 | 2 | - | 2026-04-02 |
| AC11 Router | 1 | 1 | 2021-11-03 |
| AC1206 | 1 | - | 2026-01-05 |
| AC1900 Router AC15 Model | 1 | 1 | 2021-11-03 |
| AC7, AC9, and AC10 Routers | 1 | 1 | 2021-11-03 |
| AC8 | 1 | - | 2026-03-16 |
| CH22 | 1 | - | 2026-03-30 |
| F456 | 1 | - | 2026-04-27 |
Security Advisories
Weakness Types
All Tenda CVEs
15 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2021-31755 | Tenda AC11 Router Stack Buffer Overflow Vulnerability | - | 9.8 | 86.5% | KEV | 2021-05-07 |
| CVE-2020-10987 | Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability | - | 9.8 | 79.8% | KEV | 2020-07-13 |
| CVE-2018-14558 | Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability | - | 9.8 | 8.5% | KEV | 2018-10-30 |
| CVE-2026-5339 | Tenda G103 Setting gpon.lua action_set_net_settings command injection | Tenda | 5.8 | 10.2% | 2026-04-02 | |
| CVE-2026-0581 | Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection | Tenda | 6.5 | 9.4% | 2026-01-05 | |
| CVE-2026-8263 | Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection | Tenda | 5.8 | 8.7% | 2026-05-11 | |
| CVE-2026-5338 | Tenda G103 Setting system.lua action_set_system_settings command injection | Tenda | 5.8 | 8.3% | 2026-04-02 | |
| CVE-2026-8259 | Tenda AC6 httpd telnet os command injection | Tenda | 5.8 | 8.3% | 2026-05-11 | |
| CVE-2026-8265 | Tenda AC6 httpd getLogFile get_log_file os command injection | Tenda | 5.8 | 8.3% | 2026-05-11 | |
| CVE-2026-4253 | Tenda AC8 Web UploadCfg route_set_user_policy_rule os command injection | Tenda | 5.8 | 8.2% | 2026-03-16 | |
| CVE-2026-4554 | Tenda F453 WriteFacMac FormWriteFacMac privilege escalation | Tenda | 6.5 | 6.5% | 2026-03-22 | |
| CVE-2026-5153 | Tenda CH22 WriteFacMac FormWriteFacMac command injection | Tenda | 6.5 | 6.5% | 2026-03-30 | |
| CVE-2026-7102 | Tenda F456 httpd WriteFacMac FromWriteFacMac command injection | Tenda | 6.5 | 6.5% | 2026-04-27 | |
| CVE-2026-8264 | Tenda AC6 httpd WifiApScan formWifiApScan os command injection | Tenda | 6.5 | 6.5% | 2026-05-11 | |
| CVE-2026-6989 | Tenda F453 Telnet Service telnet TendaTelnet command injection | Tenda | 6.5 | 6.3% | 2026-04-25 |
Frequently Asked Questions
How many Tenda vulnerabilities are actively exploited?→
3 Tenda CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2021-11-03.
Which Tenda products have the most exploited vulnerabilities?→
- +AC6: 4 CVEs (0 in KEV)
- +F453: 2 CVEs (0 in KEV)
- +G103: 2 CVEs (0 in KEV)
- +AC11 Router: 1 CVE (1 in KEV)
- +AC1206: 1 CVE (0 in KEV)
Where does Tenda publish security advisories?→
Tenda publishes security advisories at https://www.tendacn.com/notices. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Tenda, MITRE, CISA, or FIRST.