AC500 Firmware
16 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for AC500 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
AC500 Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High8
- Medium4
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting AC500 Firmware.
- CVE-2025-7586Tenda AC500 setWtpData formSetAPCfg stack-based overflow8.8
- CVE-2024-10280Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference6.5
- CVE-2024-3910Tenda AC500 DhcpListClient fromDhcpListClient stack-based overflow8.8
- CVE-2024-3909Tenda AC500 execCommand formexeCommand stack-based overflow8.8
- CVE-2024-3908Tenda AC500 WriteFacMac formWriteFacMac command injection6.3
- CVE-2024-3907Tenda AC500 setcfm formSetCfm stack-based overflow8.8
- CVE-2024-3906Tenda AC500 QuickIndex formQuickIndex stack-based overflow8.8
- CVE-2024-3905Tenda AC500 execCommand R7WebsSecurityHandler stack-based overflow8.8
- CVE-2024-32320Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function.5.9
- CVE-2024-32318Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.9.8
- CVE-2024-32314Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.3.8
- CVE-2024-32316Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.6.5
- CVE-2023-46060A Buffer Overflow vulnerability in Tenda AC500 v.2.0.1.9 allows a remote attacker to cause a denial of service via the port parameter at the goform/setVlanInfo component.7.5
- CVE-2023-25235Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid.7.5
- CVE-2023-25233Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.9.8
Product grouping is registry-driven, with AI assist and human review. How it works