Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.96% | — | Tenda A18 Firmware | 21/2/2026 | 17/6/2026 | A vulnerability was determined in Tenda A18 15.13.07.13. This affects the function parse_macfilter_rule of the file /goform/setBlackRule. This manipulation of the argument deviceList causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda A21 Firmware | 21/2/2026 | 17/6/2026 | A flaw has been found in Tenda A21 1.0.0.0. Impacted is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. Executing a manipulation of the argument ssid can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda A21 Firmware | 21/2/2026 | 17/6/2026 | A vulnerability was detected in Tenda A21 1.0.0.0. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda A21 Firmware | 21/2/2026 | 17/6/2026 | A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. Such manipulation of the argument devName/mac leads to stack-based buffer overflow. The attack may be… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda A21 Firmware | 21/2/2026 | 17/6/2026 | A weakness has been identified in Tenda A21 1.0.0.0. This affects the function fromSetIpMacBind of the file /goform/SetIpMacBind. This manipulation of the argument list causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda A21 Firmware | 21/2/2026 | 17/6/2026 | A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipulation of the argument list results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be… | |
| Analizada | Alta (7.4) | 0.83% | — | Tenda AC8 Firmware | 9/2/2026 | 17/6/2026 | A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This manipulation of the argument timeZone causes buffer overflow. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Alta (7.4) | 0.83% | — | Tenda AC8 Firmware | 9/2/2026 | 17/6/2026 | A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. The manipulation of the argument shareSpeed results in buffer overflow. The attack may be launched remotely. The exploit is now public and may be used. | |
| Analizada | Alta (7.3) | 0.77% | — | Tenda AC9 Firmware | 8/2/2026 | 17/6/2026 | A security vulnerability has been detected in Tenda AC9 15.03.06.42_multi. Affected by this vulnerability is the function formGetRebootTimer. Such manipulation of the argument sys.schedulereboot.start_time/sys.schedulereboot.end_time leads to stack-based buffer overflow. The attack may be launched remotely. The… | |
| Analizada | Alta (7.3) | 0.77% | — | Tenda AC9 Firmware | 8/2/2026 | 17/6/2026 | A weakness has been identified in Tenda AC9 15.03.06.42_multi. Affected is the function formGetDdosDefenceList. This manipulation of the argument security.ddos.map causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. | |
| Analizada | Alta (7.4) | 0.92% | — | Tenda RX3 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could… | |
| Analizada | Alta (7.4) | 0.92% | — | Tenda RX3 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability has been found in Tenda RX3 16.03.13.11. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument list leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.4) | 0.76% | — | Tenda RX3 Firmware | 8/2/2026 | 17/6/2026 | A flaw has been found in Tenda RX3 16.03.13.11. This issue affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. This manipulation of the argument devName/mac causes stack-based buffer overflow. The attack is possible to be carried out remotely.… | |
| Analizada | Alta (7.4) | 0.66% | — | Tenda RX3 Firmware | 8/2/2026 | 17/6/2026 | A security flaw has been discovered in Tenda RX3 16.03.13.11. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has… | |
| Analizada | Alta (7.4) | 0.64% | — | Tenda RX3 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability was identified in Tenda RX3 16.03.13.11. Affected is an unknown function of the file /goform/fast_setting_wifi_set. Such manipulation of the argument ssid_5g leads to stack-based buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.61% | — | Tenda Ac21 Firmware | 8/2/2026 | 17/6/2026 | A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-bin/DownloadFlash of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed publicly… | |
| Analizada | Media (5.5) | 0.59% | — | Tenda Ac21 Firmware | 8/2/2026 | 17/6/2026 | A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/DownloadLog of the component Web Management Interface. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. The exploit has been made available to the public… | |
| Analizada | Alta (7.4) | 0.83% | — | Tenda TX9 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipulation of the argument deviceList leads to buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (7.4) | 0.72% | — | Tenda TX9 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability was determined in Tenda TX9 up to 22.03.02.10_multi. Affected by this vulnerability is the function sub_432580 of the file /goform/fast_setting_wifi_set. This manipulation of the argument ssid causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may… | |
| Analizada | Alta (7.4) | 0.83% | — | Tenda TX9 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability was found in Tenda TX9 up to 22.03.02.10_multi. Affected is the function sub_42D03C of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (7.4) | 0.83% | — | Tenda TX3 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /goform/SetIpMacBind. The manipulation of the argument list leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (8.6) | 3.2% | 💥 PoC | Tenda G300-f Firmware | 7/2/2026 | 17/6/2026 | Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the command line without adequate neutralization.… | |
| Analizada | Alta (8.2) | 0.23% | — | Tenda AC7 Firmware | 3/2/2026 | 17/6/2026 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material. | |
| Analizada | Media (5.1) | 0.17% | — | Tenda AC7 Firmware | 3/2/2026 | 17/6/2026 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform… | |
| Analizada | Media (6.8) | 0.14% | — | Tenda AC7 Firmware | 3/2/2026 | 17/6/2026 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose sensitive information in web management responses. Administrative credentials, including the router and/or admin panel password, are included in plaintext within configuration response bodies. In addition, responses lack appropriate Cache-Control… |