Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.4% | — | Tenda Ac1206AI | 31/8/2026 | 31/8/2026 | A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Tenda Hg10AIBOA WEB ServerAI | 30/8/2026 | 1/9/2026 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 2.7% | — | Tenda Ch22AI | 23/8/2026 | 27/8/2026 | A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Baja (2.1) | 2.7% | — | Tenda Ch22AI | 23/8/2026 | 24/8/2026 | A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Baja (2.1) | 2.7% | — | Tenda Ch22AI | 20/8/2026 | 24/8/2026 | A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Tenda W20eAI | 17/8/2026 | 9/9/2026 | Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819 | |
| Aplazada | Crítica (9.8) | 0.59% | — | Tenda W20eAI | 17/8/2026 | 31/8/2026 | Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access. | |
| Aplazada | Alta (8.9) | 1.4% | — | Tenda Ac10AI | 16/8/2026 | 20/8/2026 | A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda W20eAI | 14/8/2026 | 14/8/2026 | A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda W20eAI | 14/8/2026 | 18/8/2026 | A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda W20eAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the argument qosListConnecttedNum leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Ac12AI | 14/8/2026 | 18/8/2026 | A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd web management interface. This manipulation of the argument rebootTime causes buffer overflow. The attack may be initiated… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda G0AI | 14/8/2026 | 14/8/2026 | A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component httpd web management interface. Performing a manipulation of the argument portMappingServer/porMappingtInternal/portMappingExternal results in buffer overflow. The attack… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda G0AI | 14/8/2026 | 14/8/2026 | A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the component httpd web management interface. Executing a manipulation of the argument staticRouteNet can lead to stack-based buffer overflow. The attack may be performed from… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda G0AI | 14/8/2026 | 18/8/2026 | A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the component httpd Web Management Interface. Such manipulation of the argument portMirrorMirroredPorts leads to stack-based buffer overflow. The attack can be executed remotely.… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Ac1206AI | 14/8/2026 | 14/8/2026 | A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /goform/WifiGuestSet of the component httpd web management interface. This manipulation of the argument shareSpeed causes stack-based buffer overflow. Remote exploitation of… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Ac1206AI | 14/8/2026 | 18/8/2026 | A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of the component httpd web management interface. The manipulation of the argument devName results in stack-based buffer overflow. The attack may be launched remotely. The… | |
| Aplazada | Alta (8.2) | 0.81% | — | Tenda CHAITenda CPAITenda TX3AI | 13/8/2026 | 14/8/2026 | A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The… | |
| Aplazada | Baja (2.9) | 0.63% | — | Tenda CH7AITenda Ch7gAITenda Ch10AITenda CP3AI+6 | 13/8/2026 | 18/8/2026 | A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack… | |
| Aplazada | Baja (2.9) | 0.49% | — | Tenda CH7AITenda Ch7gAITenda Ch10AITenda CP3AI+6 | 13/8/2026 | 14/8/2026 | A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin Web Service. Such manipulation of the argument SESSION leads to… | |
| Aplazada | Alta (8.9) | 3.1% | — | Tenda CH7AITenda Ch7gAITenda Ch10AITenda CP3AI+6 | 13/8/2026 | 14/8/2026 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely. | |
| Aplazada | Alta (7.4) | 2.7% | — | Tenda Ch22AI | 9/8/2026 | 12/8/2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Crítica (9.8) | 0.52% | 💥 PoC | Tenda W6-sAI | 31/7/2026 | 31/8/2026 | Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow. | |
| Aplazada | Alta (7.5) | 0.49% | — | Tenda TX9AI | 20/7/2026 | 21/7/2026 | The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName | |
| Aplazada | Crítica (9.8) | 0.60% | — | Tenda TX9AI | 20/7/2026 | 21/7/2026 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName |