Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.0% | — | Tenda AC5 Firmware | 16/5/2023 | 17/6/2026 | Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac. | |
| Modificada | Crítica (9.8) | 0.76% | — | Tenda AC5 Firmware | 24/4/2023 | 17/6/2026 | Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function. | |
| Modificada | Crítica (9.8) | 0.96% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.96% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formWifiBasicSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the check_param_changed function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetWirelessRepeat function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetSysTime function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 2.1% | — | Tenda Ac15 FirmwareTenda AC5 Firmware | 28/1/2022 | 9/7/2026 | Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE. | |
| Analizada | Media (5.4) | 2.5% | 💥 Exploit | Tenda AC5 Firmware | 26/1/2021 | 17/6/2026 | A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter. |