AC18 Firmware
121 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for AC18 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
AC18 Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 9 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 4 |
| 2025-07 | 1 |
| 2025-08 | 1 |
| 2025-09 | 4 |
| 2025-10 | 9 |
| 2025-11 | 2 |
| 2025-12 | 2 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 121 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical60
- High48
- Medium13
Latest CVEs
The 15 most recently published vulnerabilities affecting AC18 Firmware.
- CVE-2026-31255A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allo...9.8
- CVE-2025-14993Tenda AC18 HTTP Request SetDlnaCfg sprintf stack-based overflow8.8
- CVE-2025-14992Tenda AC18 HTTP Request GetParentControlInfo strcpy stack-based overflow8.8
- CVE-2025-63834A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inje...5.4
- CVE-2025-63835A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attack...8.8
- CVE-2025-11328Tenda AC18 SetDDNSCfg stack-based overflow8.8
- CVE-2025-11327Tenda AC18 SetUpnpCfg stack-based overflow8.8
- CVE-2025-11326Tenda AC18 WifiMacFilterSet stack-based overflow8.8
- CVE-2025-11325Tenda AC18 fast_setting_pppoe_set stack-based overflow8.8
- CVE-2025-11324Tenda AC18 setNotUpgrade stack-based overflow8.8
- CVE-2025-60661Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.5.3
- CVE-2025-60660Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.7.5
- CVE-2025-60662Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.7.5
- CVE-2025-60663Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.7.5
- CVE-2025-11123Tenda AC18 saveAutoQos stack-based overflow8.8
Product grouping is registry-driven, with AI assist and human review. How it works