Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.39%—Tenda AC6 Firmware20/8/202517/6/2026
A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted series of HTTP requests can lead to a reboot. An attacker can send multiple network packets to trigger this vulnerability.
ModificadaCrítica (9.8)2.1%—Tenda AC6 Firmware20/8/202517/6/2026
An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.
ModificadaAlta (7.5)0.37%—Tenda AC6 Firmware20/8/202517/6/2026
An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.
ModificadaCrítica (9.8)0.57%—Tenda AC6 Firmware20/8/202517/6/2026
An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lead to arbitrary code execution. An attacker can browse to the device to trigger this vulnerability.
AnalizadaAlta (8.7)0.87%—Tenda AC6 Firmware21/7/202517/6/2026
A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the component httpd. The manipulation leads to buffer overflow. The attack can be launched remotely.
AnalizadaAlta (8.1)0.46%—Tenda AC6 Firmware3/7/202517/6/2026
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.
AnalizadaAlta (7.5)0.45%—Tenda AC6 Firmware3/7/202517/6/2026
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.
AnalizadaAlta (7.5)0.45%—Tenda AC6 Firmware3/7/202517/6/2026
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.
AnalizadaAlta (8.1)0.46%—Tenda AC6 Firmware3/7/202517/6/2026
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.
ModificadaMedia (6.5)0.43%—Tenda AC6 Firmware1/7/202517/6/2026
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId.
AnalizadaAlta (7.3)0.38%—Tenda AC6 Firmware27/6/202517/6/2026
A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.
ModificadaAlta (7.5)0.63%—Tenda AC6 Firmware12/6/20255/7/2026
Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated HTTP GET request to the /goform/openSchedWifi endpoint
AnalizadaAlta (7.4)1.0%—Tenda AC6 Firmware9/6/202517/6/2026
A vulnerability, which was classified as critical, was found in Tenda AC6 15.03.05.16. This affects the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaAlta (7.4)0.96%—Tenda AC6 Firmware9/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to…
AnalizadaAlta (7.4)7.1%—Tenda AC6 Firmware9/6/202517/6/2026
A vulnerability classified as critical was found in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…
AnalizadaAlta (7.4)0.99%—Tenda AC6 Firmware9/6/202517/6/2026
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (6.5)0.28%—Tenda AC6 Firmware2/6/202517/6/2026
Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.
AnalizadaAlta (7.5)0.47%—Tenda AC6 Firmware20/3/202517/6/2026
A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.
ModificadaCrítica (9.8)0.48%—Tenda AC6 Firmware14/3/202517/6/2026
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.
ModificadaCrítica (9.8)0.48%—Tenda AC6 Firmware14/3/202517/6/2026
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.
ModificadaCrítica (9.8)0.48%—Tenda AC6 Firmware14/3/202517/6/2026
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
AnalizadaAlta (8.7)1.0%—Tenda AC6 Firmware2/3/202517/6/2026
A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected by this issue is some unknown functionality of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has…
AnalizadaMedia (6.5)0.53%—Tenda AC6 Firmware21/2/202517/6/2026
There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.
AnalizadaMedia (6.5)0.30%—Tenda AC6 Firmware21/2/202517/6/2026
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.
ModificadaCrítica (9.8)0.71%—Tenda AC6 Firmware12/2/202517/6/2026
Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
Orbitaley — Vulnerabilidades