CVE Tools

AC9 Firmware

109 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for AC9 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

AC9 Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
AC9 Firmware CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-012
2025-020
2025-035
2025-043
2025-053
2025-064
2025-070
2025-081
2025-094
2025-100
2025-110
2025-121
2026-010
2026-022
2026-030
2026-042
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 109 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical6459%
  • High3431%
  • Medium109%
  • Low11%

Latest CVEs

The 15 most recently published vulnerabilities affecting AC9 Firmware.

  1. CVE-2026-6016Tenda AC9 POST Request WizardHandle decodePwd stack-based overflow8.8
  2. CVE-2026-6015Tenda AC9 POST Request QuickIndex formQuickIndex stack-based overflow8.8
  3. CVE-2026-2192Tenda AC9 formGetRebootTimer stack-based overflow7.2
  4. CVE-2026-2191Tenda AC9 formGetDdosDefenceList stack-based overflow7.2
  5. CVE-2025-14286Tenda AC9 Configuration File DownloadCfg.jpg information disclosure5.3
  6. CVE-2025-57638Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.7.5
  7. CVE-2025-57639OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd ...6.5
  8. CVE-2025-10443Tenda AC9/AC15 exeCommand formexeCommand buffer overflow8.8
  9. CVE-2025-10442Tenda AC9/AC15 exeCommand formexeCommand os command injection6.3
  10. CVE-2025-9731Tenda AC9 Administrative shadow hard-coded credentials2.5
  11. CVE-2025-5900Tenda AC9 cross-site request forgery4.3
  12. CVE-2025-5847Tenda AC9 HTTP POST Request SetRemoteWebCfg formSetSafeWanWebMan stack-based overflow8.8
  13. CVE-2025-5839Tenda AC9 POST Request AdvSetLanip fromadvsetlanip buffer overflow8.8
  14. CVE-2025-5836Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection6.3
  15. CVE-2025-45042Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store