Vendor
Tenda vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 194 vulnerabilities in Tenda: 0 in the last 7 days and 62 in the last 90 days, 20 of them critical and 3 exploited in the wild. The most recent, CVE-2026-90689, was published on 14 September 2026. 45 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 62
- Critical, all time
- 20
- Exploited in the wild
- 3
About Tenda
A manufacturer of networking devices and equipment.
Tenda technologies
- Tenda F45116
- Tenda CP314
- Tenda F451 Firmware13
- Tenda W20E11
- Tenda G010
- Tenda W15E10
- Tenda HG108
- Tenda W3 Wireless Router8
- Tenda CH227
- Tenda CX12L7
- Tenda CX12L Firmware7
- Tenda 5G036
- Tenda AC106
- Tenda AC86
- Tenda Ac8 Firmware6
- Tenda BE12 Pro6
- Tenda F36
- Tenda AC10 Firmware5
- Tenda AC12065
- Tenda AC65
- Tenda AC6 firmware5
- Tenda AC75
- Tenda CP3 V3.0 firmware5
- Tenda F3 Firmware5
- Tenda JD12L Pro5
- Tenda O35
- Tenda TX9 Pro5
- Tenda W125
- Tenda AC8V44
- Tenda Ac94
- Tenda CX12L Router4
- Tenda F12024
- Tenda AC153
- Tenda Ac9 Firmware3
- Tenda CH103
- Tenda Ch22 Firmware3
- Tenda CH73
- Tenda CH7G3
- Tenda CP3 Pro3
- Tenda CP73
- Tenda PW201A3
- Tenda TC3B14C3
- Tenda TC3B15C3
- Tenda TC3T14C3
- Tenda TC3T15C3
Latest Tenda vulnerabilities
- CVE-2026-90689: Tenda W20E stack buffer overflow in formDelWebAuthWhiteUserhighCVSS 8.8EPSS 0.9%
- CVE-2026-90688: Tenda W20E stack buffer overflow in formIPMacBindAddmediumCVSS 6.5EPSS 0.7%
- CVE-2026-86300: Tenda AC9 authentication bypass in web managementhighCVSS 7.3EPSS 0.8%
- CVE-2026-86167: Tenda HG10 OS command injection in formgponConfcriticalCVSS 9.9EPSS 2.7%
- CVE-2026-86166: Tenda HG10 buffer overflow in formWanRedirecthighCVSS 8.8EPSS 0.9%
- CVE-2026-86165: Tenda HG10 buffer overflow in formURLcriticalCVSS 9.8EPSS 1.1%
- CVE-2026-86153: Tenda CP3 privilege escalation in redirect servercriticalCVSS 9.1EPSS 0.7%
- CVE-2026-86152: Tenda CP3 OS command injection in AutoAddWificriticalCVSS 10EPSS 2.9%
- CVE-2026-86151: Tenda CP3 OS command injection in Network Configuration ManagementcriticalCVSS 9.1EPSS 2.9%
- CVE-2026-86150: Tenda CP3 hard-coded credentials in hostapd configurationmediumCVSS 4.1EPSS 0.4%
- CVE-2026-86149: Tenda CP3 OS command injection via interface_name argumentcriticalCVSS 9.1EPSS 2.9%
- CVE-2026-86148: Tenda CP3 OS command injection in SystemAshcriticalCVSS 9.1EPSS 2.9%
- CVE-2026-85110: Tenda HG10 buffer overflow in formWlanSetup SSID parameterhighCVSS 8.8EPSS 0.9%
- CVE-2026-85109: Tenda HG10 buffer overflow in Boa Web Server login handlercriticalCVSS 9.8EPSS 1.1%
- CVE-2026-51934: Tenda A18 buffer overflow in fromSetCmdlineRuncriticalCVSS 9.8EPSS 1.1%
- CVE-2026-38577: Tenda HG21 hardcoded credentials in admin accountcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-82695: Tenda AC18 authentication bypass in telnet handlercriticalCVSS 10EPSS 1.4%
- CVE-2026-82694: Tenda AC1206 authentication bypass in Web UIcriticalCVSS 10EPSS 1.4%
- CVE-2026-82693: Tenda AC1206 authentication bypass in web UI telnet functioncriticalCVSS 10EPSS 1.4%
- CVE-2026-82542: Tenda HG10 buffer overflow in formIPv6RoutingcriticalCVSS 10EPSS 1.1%
- CVE-2026-78141: Tenda CH22 command injection in formexeCommandhighCVSS 7.4EPSS 2.8%
- CVE-2026-78063: Tenda CH22 command injection in editFileNamehighCVSS 7.4EPSS 2.8%
- CVE-2026-77031: Tenda CH22 command injection in formcreateFileNamehighCVSS 7.4EPSS 2.8%
- CVE-2026-19792: Tenda G0 buffer overflow in setPortMappinghighCVSS 8.8EPSS 0.9%
- CVE-2026-19791: Tenda G0 stack buffer overflow in addStaticRoutehighCVSS 8.8EPSS 0.9%
Most severe Tenda vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2020-10987: Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-31755: Tenda AC11 Router Stack Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2026-86152: Tenda CP3 OS command injection in AutoAddWificriticalCVSS 10EPSS 2.9%
- CVE-2026-82694: Tenda AC1206 authentication bypass in Web UIcriticalCVSS 10EPSS 1.4%
- CVE-2026-82693: Tenda AC1206 authentication bypass in web UI telnet functioncriticalCVSS 10EPSS 1.4%
- CVE-2026-82695: Tenda AC18 authentication bypass in telnet handlercriticalCVSS 10EPSS 1.4%
- CVE-2026-82542: Tenda HG10 buffer overflow in formIPv6RoutingcriticalCVSS 10EPSS 1.1%
- CVE-2026-86167: Tenda HG10 OS command injection in formgponConfcriticalCVSS 9.9EPSS 2.7%
- CVE-2026-19747: Tenda Smart Camera command injection in ATE ModulecriticalCVSS 9.8EPSS 3.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 6 | 0 | |
| 6 Jul 2026 | 8 | 0 | |
| 13 Jul 2026 | 8 | 0 | |
| 20 Jul 2026 | 7 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 9 | 1 | |
| 17 Aug 2026 | 3 | 0 | |
| 24 Aug 2026 | 1 | 1 | |
| 31 Aug 2026 | 16 | 13 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/tenda.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Tenda vulnerabilities", https://junglewise.ai/threats/vendors/tenda, 26 September 2026.