Skip to content
COOEY

FAIL › dossier

i29

PRODUCT

· dossier confidence 20%

The Tenda i29 wireless router is a networking device that suffered a catastrophic security failure in late 2023, with a single firmware version containing nine critical vulnerabilities including remote code execution and buffer overflows. This pattern of unpatched, severely flawed edge devices poses a significant risk to defense-industrial-base networks relying on such hardware.

PROFILE
Categorynetworking hardwareWhat they doTenda i29 is a wireless router manufactured by Tenda Technology. Websitehttps://www.tenda.com ↗
SECURITY POSTURE

The Tenda i29 router exhibits a critically poor security posture, with a single firmware version (v1.0 V1.0.0.5) containing nine critical vulnerabilities discovered simultaneously in December 2023, including multiple remote code execution (RCE) and buffer overflow flaws.

Notable failures
  • CVE-2023-50983: Command injection via sysScheduleRebootSet
  • CVE-2023-50989: Command injection via pingSet
  • CVE-2023-50985: Buffer overflow via lanGw parameter
Patterns: repeated unpatched edge-device RCEs; multiple buffer overflows in single firmware release
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2023-12-20 CVE-2023-50983 critical Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
2023-12-20 CVE-2023-50989 critical Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
2023-12-20 CVE-2023-50985 critical Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.
2023-12-20 CVE-2023-50986 critical Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.
2023-12-20 CVE-2023-50988 critical Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.
2023-12-20 CVE-2023-50990 critical Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.
2023-12-20 CVE-2023-50987 critical Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.
2023-12-20 CVE-2023-50992 critical Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.
2023-12-20 CVE-2023-50984 critical Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.
Open questions: When was the Tenda i29 firmware v1.0 V1.0.0.5 patched? · What is the current production status of the Tenda i29 router?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-18 04:03:30.383336+00:00