FAIL › dossier
tenda
VENDOR· dossier confidence 40%
Tenda is a Chinese router manufacturer with a documented history of ignoring critical security vulnerabilities, including a 2026 unpatched backdoor that grants admin access regardless of password.
PROFILE
CategoryvendorWhat they doTenda is a Chinese manufacturer of consumer networking equipment, primarily routers and Wi-Fi devices.HQShenzhen, China
Websitehttps://www.tendacn.com ↗
SECURITY POSTURE
Tenda demonstrates a critical failure in security governance, evidenced by a pattern of ignoring vulnerability disclosures and failing to patch critical flaws in firmware.
Notable failures
- CVE-2026-11405: Unpatched admin backdoor allowing passwordless access
- CVE-2026-51846: Critical RCE via stack buffer overflow in AC7 firmware
- CVE-2023-50989: Command injection in Tenda i29 firmware
Patterns: Repeated unpatched critical RCE vulnerabilities; Ignoring CERT/CC vulnerability disclosures; Hardcoded administrative backdoors in firmware
FAILURE HISTORY · 23
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-31755 | high | Tenda AC11 routers have an unpatched stack buffer overflow allowing remote code execution via a crafted HTTP request. |
| 2021-11-03 | CVE-2018-14558 | high | Tenda AC7, AC9, and AC10 routers allow remote command execution via a command injection flaw in the formsetUsbUnload function. |
| 2021-11-03 | CVE-2020-10987 | high | Tenda AC1900 routers allow remote attackers to execute system commands via an unpatched vulnerability in the deviceName POST parameter. |
| 2026-06-19 | CVE-2026-51846 | critical | In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution. |
| 2023-12-20 | CVE-2023-50989 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function. |
| 2023-12-20 | CVE-2023-50983 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function. |
| 2022-08-19 | CVE-2022-35201 | critical | Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability. |
| 2022-01-28 | CVE-2021-44971 | critical | Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE. |
| 2026-06-19 | CVE-2026-51844 | critical | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. |
| 2026-06-19 | CVE-2026-51845 | critical | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter. |
| 2026-06-19 | CVE-2026-51843 | critical | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. |
| 2024-11-19 | CVE-2024-52714 | critical | Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime. |
| 2024-07-09 | CVE-2023-48194 | critical | Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained. |
| 2023-12-20 | CVE-2023-50988 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function. |
| 2023-12-20 | CVE-2023-50987 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function. |
| 2023-12-20 | CVE-2023-50984 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function. |
| 2023-12-20 | CVE-2023-50985 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function. |
| 2023-12-20 | CVE-2023-50986 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function. |
| 2023-12-20 | CVE-2023-50990 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function. |
| 2023-12-20 | CVE-2023-50992 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function. |
| 2026-05-11 | CVE-2026-8263 | medium | CVE-2026-8263: A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affect |
| 2026-04-08 | CVE-2025-52221 | critical | CVE-2025-52221: Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm f |
| 2026-04-04 | CVE-2026-5526 | high | CVE-2026-5526: A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/ |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
CVE-2021-44971 represents a critical authentication bypass vulnerability in Tenda devices, enabling attackers to obtain sensitive information and execute remote code execution (RCE) when combined with
synthesissevere-fallout-0.60
Vulnerability allows remote code execution, a critical flaw with severe security implications.
synthesissevere-fallout-0.60
Tenda's vulnerability allowed remote code execution, a critical flaw with severe security implications, though the provided source is purely factual without commentary on Tenda's response or handling.
synthesissevere-fallout-0.60
Command injection in consumer routers is a severe security failure, allowing full OS command execution, though the provided source is a neutral NVD entry without commentary on Tenda's response.
Critical security backdoor
"These popular Tenda routers have an unpatched security backdoor which could give hackers access"
Neutral database listing
Neutral database listing
Neutral advisory page
Critical vulnerability disclosure
"Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE."
Neutral database listing
Neutral database listing
neutral
"Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the 'formsetUsbUnload' function executes a dosystemCmd function with untrusted input."
Critical flaw allowing remote code execution.
"Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request."
Factual reporting of a critical vulnerability; no commentary on vendor response provided in the source.
"Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter."
DOSSIER SOURCES
- 深圳市吉祥腾达科技有限公司 - 企查查 · www.qcc.com
- Tenda Technology Brand Review & Guide for South Africa (Tenda) Buy from ... · www.comx-computers.co.za
- Cadence Design Systems (CDNS) Company Profile, History, Products & Services · www.financecharts.com
- Hidden backdoor in Tenda routers goes unpatched as company ignores ... · www.tomshardware.com
- CVE-2026-11405: CERT Warns Of Tenda Firmware Backdoor · thecyberexpress.com
- Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices · SecurityWeek
- Tenda firmware backdoor grants administrative access to network devices · fieldeffect.com
- Tenda Firmware Backdoor Lets Anyone Log In as Admin Regardless of Password · www.techtimes.com
- Tenda Router CVE-2026-11405 Backdoor Allows Adm… | PurpleOps · purple-ops.io
Open questions: Tenda's current patch management process and response time to critical vulnerabilities · Scope of affected devices in the CERT backdoor warning (CVE-2026-11405)
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:00:47.350287+00:00