{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T15:52:24.927","vulnerabilities":[{"cve":{"id":"CVE-2018-14559","sourceIdentifier":"cve@mitre.org","published":"2019-04-25T20:29:00.287","lastModified":"2026-06-17T01:41:11.647","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow."},{"lang":"es","value":"Se descubrió un problema en los dispositivos Tenda AC7 con firmware a través de la versión V15.03.06.44_CN (AC7), dispositivos AC9 con firmware a través de la versión V15.03.05.19 (6318) _CN (AC9), y dispositivos AC10 con firmware a través de la versión V15.03.06.23_CN ( AC10). Existe una vulnerabilidad de desbordamiento de búfer en el servidor web del router (httpd). Cuando son procesados los parámetros list para una solicitud post, el valor se escribe directamente con sprintf en una variable local colocada en la pila, que anula la dirección de retorno de la función, lo que provoca un desbordamiento del búfer."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-119"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tenda:ac7_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"15.03.06.44_cn","matchCriteriaId":"B16592CE-98A8-478A-94E1-DF628ADE67E7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tenda:ac7:-:*:*:*:*:*:*:*","matchCriteriaId":"A3BEE979-5BF3-48ED-AF42-0546D4F896E9"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tenda:ac9_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"15.03.05.19\\(6318\\)_cn","matchCriteriaId":"73D523BB-7EB3-4125-90C4-4C85F4AE1815"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tenda:ac9:-:*:*:*:*:*:*:*","matchCriteriaId":"2FD1430E-DC2E-4042-9389-1FD90ECDBE4D"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tenda:ac10_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"15.03.06.23_cn","matchCriteriaId":"9BDE03D1-5D87-4FCD-BB03-D483AB9BC186"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tenda:ac10:-:*:*:*:*:*:*:*","matchCriteriaId":"B9E0489C-31D5-43C4-B15D-1D88119EF226"}]}]}],"references":[{"url":"https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-02/Tenda.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-02/Tenda.md","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}