Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.91% | — | Tendacn Ac10u Firmware | 26/1/2024 | 17/6/2026 | A vulnerability has been found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This vulnerability affects the function formSetVirtualSer. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.91% | — | Tenda Ac10u Firmware | 26/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function formSetPPTPServer. The manipulation of the argument startIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.89% | — | Tendacn Ac10u Firmware | 26/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.89% | — | Tendacn Ac10u Firmware | 26/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this vulnerability is the function formQuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 1.1% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the formSetClientState function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the mac parameter in the GetParentControlInfo function. | |
| Modificada | Crítica (9.8) | 16% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function. | |
| Modificada | Crítica (9.8) | 0.79% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the setSchedWifi function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain multiple stack overflows in the formSetMacFilterCfg function via the macFilterType and deviceList parameters. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tendacn Ac10u Firmware | 27/9/2023 | 17/6/2026 | Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the list parameter in the fromSetIpMacBind function. | |
| Modificada | Crítica (9.8) | 2.5% | — | Tendacn Ac10u Firmware | 18/2/2022 | 17/6/2026 | A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client controlled "deviceName" value is passed directly to the "doSystemCmd" function. | |
| Modificada | Crítica (9.8) | 4.2% | — | Tendacn Ac10u FirmwareTendacn AC9 Firmware | 29/10/2021 | 17/6/2026 | Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg. |