CVE Tools

Tenda AC9

27 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Tenda AC9, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Tenda AC9 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Tenda AC9 CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-035
2025-040
2025-052
2025-064
2025-070
2025-080
2025-093
2025-100
2025-110
2025-120
2026-010
2026-022
2026-030
2026-042
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 27 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1244%
  • High933%
  • Medium622%

Latest CVEs

The 15 most recently published vulnerabilities affecting Tenda AC9.

  1. CVE-2026-6016Tenda AC9 POST Request WizardHandle decodePwd stack-based overflow8.8
  2. CVE-2026-6015Tenda AC9 POST Request QuickIndex formQuickIndex stack-based overflow8.8
  3. CVE-2026-2192Tenda AC9 formGetRebootTimer stack-based overflow7.2
  4. CVE-2026-2191Tenda AC9 formGetDdosDefenceList stack-based overflow7.2
  5. CVE-2025-57638Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.7.5
  6. CVE-2025-57639OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd ...6.5
  7. CVE-2025-10442Tenda AC9/AC15 exeCommand formexeCommand os command injection6.3
  8. CVE-2025-5900Tenda AC9 cross-site request forgery4.3
  9. CVE-2025-5847Tenda AC9 HTTP POST Request SetRemoteWebCfg formSetSafeWanWebMan stack-based overflow8.8
  10. CVE-2025-5839Tenda AC9 POST Request AdvSetLanip fromadvsetlanip buffer overflow8.8
  11. CVE-2025-5836Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection6.3
  12. CVE-2025-45042Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.9.8
  13. CVE-2025-44877Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitr...9.8
  14. CVE-2025-29386In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.9.8
  15. CVE-2025-29385In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store