Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.9) | 0.86% | — | Tenda Ch22 Firmware | 8/10/2025 | 17/6/2026 | A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing a manipulation of the argument page results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (8.9) | 6.7% | — | Tenda Ch22 Firmware | 8/10/2025 | 17/6/2026 | A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component HTTP Request Handler. The manipulation of the argument mit_ssid_index leads to stack-based buffer overflow. The attack may be initiated remotely.… | |
| Analizada | Alta (7.4) | 0.80% | — | Tenda Ch22 Firmware | 28/9/2025 | 17/6/2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formWrlExtraGet of the file /goform/GstDhcpSetSer. This manipulation of the argument dips causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (7.4) | 0.87% | — | Tenda Ch22 Firmware | 2/9/2025 | 25/9/2026 | A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /goform/SetSambaConf. The manipulation of the argument samba_userNameSda leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (7.4) | 0.66% | — | Tenda Ch22 Firmware | 2/9/2025 | 25/9/2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Executing manipulation of the argument cmdinput can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (8.7) | 0.84% | — | Tenda Ch22 Firmware | 31/8/2025 | 17/6/2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. Affected by this issue is the function fromIpsecitem of the file /goform/IPSECsave of the component httpd. Executing manipulation of the argument ipsecno can lead to stack-based buffer overflow. The attack may be performed from remote. | |
| Analizada | Alta (7.4) | 0.76% | — | Tenda Ch22 Firmware | 26/8/2025 | 17/6/2026 | A flaw has been found in Tenda CH22 1.0.0.1. This vulnerability affects the function formeditUserName of the file /goform/editUserName. Executing manipulation of the argument new_account can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Analizada | Alta (7.4) | 0.73% | — | Tenda Ch22 Firmware | 15/8/2025 | 17/6/2026 | A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the file /goform/editFileName. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.4) | 0.99% | — | Tenda Ch22 Firmware | 15/8/2025 | 17/6/2026 | A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file /goform/delFileName. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.4) | 9.6% | — | Tenda Ch22 Firmware | 26/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formdeleteUserName of the file /goform/deleteUserName. The manipulation of the argument old_account leads to buffer overflow. The attack may be launched remotely. The exploit has been… | |
| Analizada | Alta (8.7) | 0.99% | — | Tenda Ch22 Firmware | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tenda CH22 1.0.0.1. This affects the function formNatlimit of the file /goform/Natlimit. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.7) | 1.3% | — | Tenda Ch22 Firmware | 4/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. This issue affects the function formaddUserName of the file /goform/addUserName. The manipulation of the argument Password leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 0.58% | — | Tenda Ch22 Firmware | 13/9/2024 | 17/6/2026 | Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function. | |
| Analizada | Crítica (9.8) | 0.62% | — | Tenda Ch22 Firmware | 13/9/2024 | 17/6/2026 | CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function. |