WeiKanghong

3 exploits Active since Nov 2025
CVE-2026-31255 WRITEUP CRITICAL WRITEUP
Tenda AC18 V15.03.05.05 - Command Injection
A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.
CVSS 9.8
CVE-2025-63834 WRITEUP MEDIUM WRITEUP
Tenda AC18 <15.03.05.05_multi - XSS
A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.
CVSS 5.4
CVE-2025-63835 WRITEUP HIGH WRITEUP
Tenda AC18 v15.03.05.05_multi - Buffer Overflow
A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.
CVSS 8.8