Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.68% | — | Tenda AC9 Firmware | 9/12/2025 | 7/10/2026 | Se determinó una vulnerabilidad en Tenda AC9 15.03.05.14_multi. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /cgi-bin/DownloadCfg.jpg del componente Gestor de Archivos de Configuración. Esta manipulación provoca revelación de información. El ataque puede iniciarse remotamente. El exploit se… | |
| Analizada | Media (6.5) | 0.55% | — | Tenda AX3 Firmware | 8/12/2025 | 17/6/2026 | Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corruption and enable remote code execution (RCE). | |
| Analizada | Media (4.3) | 0.24% | — | Tenda Ac21 Firmware | 20/11/2025 | 17/6/2026 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo. | |
| Analizada | Media (4.3) | 0.29% | — | Tenda Ac21 Firmware | 20/11/2025 | 17/6/2026 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo. | |
| Analizada | Media (4.3) | 2.4% | — | Tenda Ac21 Firmware | 20/11/2025 | 17/6/2026 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg. | |
| Analizada | Media (4.3) | 0.29% | — | Tenda Ac21 Firmware | 20/11/2025 | 17/6/2026 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList. | |
| Analizada | Media (4.3) | 0.25% | — | Tenda Ac21 Firmware | 20/11/2025 | 17/6/2026 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter. | |
| Analizada | Alta (7.4) | 3.9% | — | Tenda Ac21 Firmware | 20/11/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone/time leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.4) | 3.9% | — | Tenda Ac21 Firmware | 20/11/2025 | 17/6/2026 | A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executing a manipulation of the argument list can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. | |
| Modificada | Alta (7.4) | 0.69% | — | Tenda Ch22 Firmware | 19/11/2025 | 17/6/2026 | A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtraGet. Performing a manipulation of the argument chkHz results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Analizada | Alta (7.4) | 0.88% | — | Tenda Ch22 Firmware | 17/11/2025 | 17/6/2026 | A security vulnerability has been detected in Tenda CH22 1.0.0.1. This impacts the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be… | |
| Analizada | Alta (7.4) | 0.74% | — | Tenda Ac20 Firmware | 17/11/2025 | 17/6/2026 | A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is an unknown function of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. | |
| Analizada | Crítica (9.8) | 0.47% | 💥 PoC | Tenda Ac15 Firmware | 12/11/2025 | 17/6/2026 | Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie and replay it to access protected… | |
| Analizada | Alta (7.5) | 0.37% | — | Tenda AX3 Firmware | 10/11/2025 | 17/6/2026 | Se descubrió que Tenda AX3 V16.03.12.10_CN contenía un desbordamiento de pila en el parámetro 'urls' de la función 'get_parentControl_list_Info'. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) mediante una solicitud manipulada. | |
| Modificada | Alta (8.8) | 0.65% | — | Tenda Ac18 Firmware | 10/11/2025 | 17/6/2026 | Una vulnerabilidad de desbordamiento de búfer basado en pila fue descubierta en Tenda AC18 v15.03.05.05_multi. La vulnerabilidad existe en el parámetro guestSsid de la interfaz /goform/WifiGuestSet. Atacantes remotos pueden explotar esta vulnerabilidad enviando datos de tamaño excesivo al parámetro guestSsid, lo que… | |
| Modificada | Media (5.4) | 0.22% | — | Tenda Ac18 Firmware | 10/11/2025 | 17/6/2026 | Una vulnerabilidad de Cross-Site Scripting (XSS) almacenado fue descubierta en Tenda AC18 v15.03.05.05_multi. La vulnerabilidad existe en el parámetro ssid de la configuración inalámbrica. Atacantes remotos pueden inyectar cargas útiles maliciosas que se ejecutan cuando cualquier usuario visita la página de inicio del… | |
| Modificada | Alta (7.5) | 0.37% | — | Tenda Ax1803 Firmware | 10/11/2025 | 17/6/2026 | Se descubrió que Tenda AX-1803 v1.0.0.1 contenía un desbordamiento de pila a través del parámetro wanMTU en la función sub_4F55C. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) a través de una solicitud manipulada. | |
| Modificada | Alta (7.5) | 0.37% | — | Tenda Ax1803 Firmware | 10/11/2025 | 17/6/2026 | Tenda AX-1803 v1.0.0.1 fue descubierto que contenía un desbordamiento de pila a través del parámetro 'time' en la función SetSysTimeCfg. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) a través de una solicitud manipulada. | |
| Analizada | Alta (7.5) | 0.38% | — | Tenda AX3 Firmware | 10/11/2025 | 17/6/2026 | Se descubrió que Tenda AX-3 v16.03.12.10_CN contenía un desbordamiento de pila a través del parámetro shareSpeed en la función fromSetWifiGusetBasic. Esta vulnerabilidad permite a los atacantes provocar una denegación de servicio (DoS) mediante una solicitud manipulada. | |
| Modificada | Alta (7.5) | 0.37% | — | Tenda AX3 Firmware | 10/11/2025 | 17/6/2026 | Se descubrió que Tenda AX3 V16.03.12.10_CN contenía un desbordamiento de pila en el parámetro deviceId de la función saveParentControlInfo. Esta vulnerabilidad permite a los atacantes provocar una Denegación de Servicio (DoS) mediante una solicitud manipulada. | |
| Analizada | Alta (7.5) | 0.37% | — | Tenda AX3 Firmware | 10/11/2025 | 25/9/2026 | Se descubrió que Tenda AX3 V16.03.12.10_CN contenía un desbordamiento de pila en el parámetro wpapsk_crypto de la función wlSetExternParameter. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) mediante una solicitud manipulada. | |
| Analizada | Alta (7.4) | 0.90% | — | Tenda Ac10 Firmware | 3/11/2025 | 17/6/2026 | A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument getui causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (7.4) | 0.87% | — | Tenda A15 Firmware | 3/11/2025 | 17/6/2026 | A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (7.4) | 5.4% | — | Tenda AC8 Firmware | 3/11/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.4) | 0.74% | — | Tenda Ac21 Firmware | 3/11/2025 | 17/6/2026 | A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. |