Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 1.2% | — | Tenda Ac18 Firmware | 6/10/2025 | 17/6/2026 | A weakness has been identified in Tenda AC18 15.03.05.19(6318). This affects an unknown part of the file /goform/WifiMacFilterSet. Executing a manipulation of the argument wifi_chkHz can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and… | |
| Modificada | Alta (7.4) | 0.80% | — | Tenda Ac18 Firmware | 6/10/2025 | 17/6/2026 | A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionality of the file /goform/fast_setting_pppoe_set. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.83% | — | Tenda Ac18 Firmware | 6/10/2025 | 17/6/2026 | A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionality of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and… | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda Ac18 Firmware | 2/10/2025 | 17/6/2026 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function. | |
| Analizada | Media (5.3) | 0.42% | — | Tenda Ac18 Firmware | 2/10/2025 | 17/6/2026 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda Ac18 Firmware | 2/10/2025 | 17/6/2026 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda Ac18 Firmware | 2/10/2025 | 17/6/2026 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function. | |
| Analizada | Alta (7.4) | 0.80% | — | Tenda Ac18 Firmware | 28/9/2025 | 17/6/2026 | A flaw has been found in Tenda AC18 15.03.05.19. This impacts an unknown function of the file /goform/saveAutoQos. This manipulation of the argument enable causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 3.7% | — | Tenda Ac18 Firmware | 28/9/2025 | 17/6/2026 | A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. The manipulation of the argument lanIp leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Alta (7.4) | 3.7% | — | Tenda Ac18 Firmware | 28/9/2025 | 17/6/2026 | A weakness has been identified in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the file /goform/SetServerConfig. Executing manipulation can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be… | |
| Analizada | Alta (7.4) | 0.80% | — | Tenda Ch22 Firmware | 28/9/2025 | 17/6/2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formWrlExtraGet of the file /goform/GstDhcpSetSer. This manipulation of the argument dips causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (7.4) | 0.80% | — | Tenda Ac18 Firmware | 28/9/2025 | 30/9/2026 | Una vulnerabilidad fue detectada en Tenda AC18 15.03.05.19. Esto afecta una función desconocida del archivo /goform/WizardHandle. La manipulación del argumento WANT/mtuvalue resulta en desbordamiento de búfer basado en pila. El ataque puede ser lanzado de forma remota. El exploit ahora es público y puede ser utilizado. | |
| Analizada | Alta (7.4) | 0.74% | — | Tenda Ac21 Firmware | 28/9/2025 | 17/6/2026 | A security flaw has been discovered in Tenda AC21 up to 16.03.08.16. Affected by this vulnerability is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be… | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda AC9 Firmware | 23/9/2025 | 17/6/2026 | Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value. | |
| Analizada | Media (6.5) | 0.98% | — | Tenda AC9 Firmware | 23/9/2025 | 17/6/2026 | OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda Ac21 Firmware | 23/9/2025 | 17/6/2026 | A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function sub_45BB10 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (7.4) | 0.83% | — | Tenda Ac20 Firmware | 22/9/2025 | 17/6/2026 | A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this issue is the function strcpy of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. The attack can be launched remotely. The exploit is publicly… | |
| Analizada | Alta (7.4) | 0.80% | — | Tenda Ac23 Firmware | 22/9/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. It is possible to launch the attack remotely. The… | |
| Analizada | Media (6.5) | 3.3% | — | Tenda AC6 Firmware | 19/9/2025 | 17/6/2026 | Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the list and vlanId parameters, the sub_ADBC0 helper function concatenates these user-supplied values into nvram set system… | |
| Analizada | Alta (7.7) | 0.44% | — | Tenda AC6 Firmware | 19/9/2025 | 17/6/2026 | An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of service via the funcname, funcpara1, funcpara2 parameters to the formSetCfm function (uri path: SetCfm). | |
| Analizada | Alta (7.4) | 4.2% | — | Tenda AC9 FirmwareTenda Ac15 Firmware | 15/9/2025 | 17/6/2026 | A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be… | |
| Analizada | Baja (2.1) | 8.7% | — | Tenda AC9 FirmwareTenda Ac15 Firmware | 15/9/2025 | 17/6/2026 | A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (8.9) | 1.6% | — | Tenda Ac1206 Firmware | 15/9/2025 | 17/6/2026 | A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function check_param_changed of the file /goform/AdvSetMacMtuWa of the component HTTP Request Handler. Performing manipulation of the argument wanMTU results in stack-based buffer overflow. Remote exploitation of the attack is… | |
| Modificada | Media (5.6) | 0.22% | — | Tenda F3 Firmware | 10/9/2025 | 5/7/2026 | Tenda F3 V12.01.01.48_multi y posterior es vulnerable a desbordamiento de búfer a través del parámetro wifiTimeClose en goform/setWifi. | |
| Modificada | Media (5.6) | 0.22% | — | Tenda F3 Firmware | 10/9/2025 | 5/7/2026 | Tenda F3 V12.01.01.48_multi y posteriores es vulnerable a desbordamiento de búfer a través del parámetro onlineList en goform/setParentControl. |