Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

2279 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.68%—Tenda AC9 Firmware9/12/20257/10/2026
Se determinó una vulnerabilidad en Tenda AC9 15.03.05.14_multi. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /cgi-bin/DownloadCfg.jpg del componente Gestor de Archivos de Configuración. Esta manipulación provoca revelación de información. El ataque puede iniciarse remotamente. El exploit se…
AnalizadaMedia (6.5)0.55%—Tenda AX3 Firmware8/12/202517/6/2026
Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corruption and enable remote code execution (RCE).
AnalizadaMedia (4.3)0.24%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.
AnalizadaMedia (4.3)0.29%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.
AnalizadaMedia (4.3)2.4%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.
AnalizadaMedia (4.3)0.29%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.
AnalizadaMedia (4.3)0.25%—Tenda Ac21 Firmware20/11/202517/6/2026
Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.
AnalizadaAlta (7.4)3.9%—Tenda Ac21 Firmware20/11/202517/6/2026
A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone/time leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and…
ModificadaAlta (7.4)3.9%—Tenda Ac21 Firmware20/11/202517/6/2026
A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executing a manipulation of the argument list can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.
ModificadaAlta (7.4)0.69%—Tenda Ch22 Firmware19/11/202517/6/2026
A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtraGet. Performing a manipulation of the argument chkHz results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.
AnalizadaAlta (7.4)0.88%—Tenda Ch22 Firmware17/11/202517/6/2026
A security vulnerability has been detected in Tenda CH22 1.0.0.1. This impacts the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be…
AnalizadaAlta (7.4)0.74%—Tenda Ac20 Firmware17/11/202517/6/2026
A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is an unknown function of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.
AnalizadaCrítica (9.8)0.47%💥 PoCTenda Ac15 Firmware12/11/202517/6/2026
Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie and replay it to access protected…
AnalizadaAlta (7.5)0.37%—Tenda AX3 Firmware10/11/202517/6/2026
Se descubrió que Tenda AX3 V16.03.12.10_CN contenía un desbordamiento de pila en el parámetro 'urls' de la función 'get_parentControl_list_Info'. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) mediante una solicitud manipulada.
ModificadaAlta (8.8)0.65%—Tenda Ac18 Firmware10/11/202517/6/2026
Una vulnerabilidad de desbordamiento de búfer basado en pila fue descubierta en Tenda AC18 v15.03.05.05_multi. La vulnerabilidad existe en el parámetro guestSsid de la interfaz /goform/WifiGuestSet. Atacantes remotos pueden explotar esta vulnerabilidad enviando datos de tamaño excesivo al parámetro guestSsid, lo que…
ModificadaMedia (5.4)0.22%—Tenda Ac18 Firmware10/11/202517/6/2026
Una vulnerabilidad de Cross-Site Scripting (XSS) almacenado fue descubierta en Tenda AC18 v15.03.05.05_multi. La vulnerabilidad existe en el parámetro ssid de la configuración inalámbrica. Atacantes remotos pueden inyectar cargas útiles maliciosas que se ejecutan cuando cualquier usuario visita la página de inicio del…
ModificadaAlta (7.5)0.37%—Tenda Ax1803 Firmware10/11/202517/6/2026
Se descubrió que Tenda AX-1803 v1.0.0.1 contenía un desbordamiento de pila a través del parámetro wanMTU en la función sub_4F55C. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) a través de una solicitud manipulada.
ModificadaAlta (7.5)0.37%—Tenda Ax1803 Firmware10/11/202517/6/2026
Tenda AX-1803 v1.0.0.1 fue descubierto que contenía un desbordamiento de pila a través del parámetro 'time' en la función SetSysTimeCfg. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) a través de una solicitud manipulada.
AnalizadaAlta (7.5)0.38%—Tenda AX3 Firmware10/11/202517/6/2026
Se descubrió que Tenda AX-3 v16.03.12.10_CN contenía un desbordamiento de pila a través del parámetro shareSpeed en la función fromSetWifiGusetBasic. Esta vulnerabilidad permite a los atacantes provocar una denegación de servicio (DoS) mediante una solicitud manipulada.
ModificadaAlta (7.5)0.37%—Tenda AX3 Firmware10/11/202517/6/2026
Se descubrió que Tenda AX3 V16.03.12.10_CN contenía un desbordamiento de pila en el parámetro deviceId de la función saveParentControlInfo. Esta vulnerabilidad permite a los atacantes provocar una Denegación de Servicio (DoS) mediante una solicitud manipulada.
AnalizadaAlta (7.5)0.37%—Tenda AX3 Firmware10/11/202525/9/2026
Se descubrió que Tenda AX3 V16.03.12.10_CN contenía un desbordamiento de pila en el parámetro wpapsk_crypto de la función wlSetExternParameter. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) mediante una solicitud manipulada.
AnalizadaAlta (7.4)0.90%—Tenda Ac10 Firmware3/11/202517/6/2026
A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument getui causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaAlta (7.4)0.87%—Tenda A15 Firmware3/11/202517/6/2026
A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
AnalizadaAlta (7.4)5.4%—Tenda AC8 Firmware3/11/202517/6/2026
A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaAlta (7.4)0.74%—Tenda Ac21 Firmware3/11/202517/6/2026
A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.