Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.8% | — | Tenda AX3 Firmware | 15/3/2023 | 17/6/2026 | Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AX3 Firmware | 15/3/2023 | 17/6/2026 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tenda AX3 Firmware | 23/2/2023 | 17/6/2026 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg. | |
| Modificada | Media (5.4) | 0.35% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail. | |
| Modificada | Alta (8.1) | 0.67% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM. | |
| Modificada | Media (6.5) | 0.66% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information. | |
| Modificada | Media (4.2) | 0.47% | — | Baxter Spectrum Wireless Battery Module FirmwareBaxter Sigma Spectrum 35700bax FirmwareBaxter Sigma Spectrum 35700bax2 FirmwareBaxter Spectrum IQ 35700bax3 Firmware | 9/9/2022 | 17/6/2026 | The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information. | |
| Modificada | Crítica (9.8) | 14% | — | Tenda AX3 Firmware | 10/3/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter. | |
| Modificada | Crítica (9.8) | 2.7% | — | Tenda AX3 Firmware | 4/3/2022 | 17/6/2026 | There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check, which causes stack overflow. By POSTing… | |
| Modificada | Crítica (9.8) | 16% | — | Tenda AX3 Firmware | 4/3/2022 | 17/6/2026 | There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security check,which causes stack overflow. By POSTing… | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a heap overflow in the function GetParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mac parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetDeviceName. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetPPTPServer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the startIp and endIp parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetIpMacBind. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetMacFilterCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the deviceList parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a heap overflow in the function setSchedWifi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the schedStartTime and schedEndTime parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetRebootTimer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the rebootTime parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formAddMacfilterRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetRouteStatic. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWifiGusetBasic. This vulnerability allows attackers to cause a Denial of Service (DoS) via the shareSpeed parameter. | |
| Modificada | Crítica (9.8) | 2.7% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebMan. This vulnerability allows attackers to execute arbitrary commands via the remoteIp parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tenda AX3 Firmware | 4/2/2022 | 17/6/2026 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetWirelessRepeat. This vulnerability allows attackers to cause a Denial of Service (DoS) via the wpapsk_crypto parameter. |