Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.6) | 0.20% | — | Tenda F3 Firmware | 10/9/2025 | 5/7/2026 | Tenda F3 V12.01.01.48_multi y posteriores es vulnerable a desbordamiento de búfer a través del parámetro macFilterList en goform/setNAT. | |
| Modificada | Media (5.6) | 0.20% | — | Tenda F3 Firmware | 10/9/2025 | 5/7/2026 | Tenda F3 V12.01.01.48_multi y posterior es vulnerable a desbordamiento de búfer a través del parámetro QosList en goform/setQoS. | |
| Modificada | Media (5.6) | 0.20% | — | Tenda F3 Firmware | 10/9/2025 | 5/7/2026 | Tenda F3 V12.01.01.48_multi y posterior es vulnerable a desbordamiento de búfer a través del parámetro portList en /goform/setNAT. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_store function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda W30e Firmware | 9/9/2025 | 17/6/2026 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Crítica (9.8) | 0.47% | — | Tenda W30e Firmware | 9/9/2025 | 17/6/2026 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the formModifyPppAuthWhiteMac function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda W30e Firmware | 9/9/2025 | 17/6/2026 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip, mac, v6 and remark parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel, and pModule parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda G3 Firmware | 9/9/2025 | 17/6/2026 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStore function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.4) | 0.85% | — | Tenda Ac20 Firmware | 9/9/2025 | 17/6/2026 | A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda AC8 Firmware | 3/9/2025 | 17/6/2026 | Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g. | |
| Analizada | Baja (2.9) | 0.34% | — | Tenda CP6 Firmware | 2/9/2025 | 30/9/2026 | Se determinó una vulnerabilidad en Tenda CP6 11.10.00.243. El elemento afectado es la función sub_2B7D04 del componente uhttp. La ejecución de manipulación puede conducir a un algoritmo criptográfico arriesgado. El ataque puede lanzarse remotamente. Este ataque se caracteriza por una alta complejidad. La… | |
| Analizada | Alta (7.4) | 0.87% | — | Tenda Ch22 Firmware | 2/9/2025 | 25/9/2026 | Se identificó una vulnerabilidad en Tenda CH22 1.0.0.1. Este problema afecta a la función formSetSambaConf del archivo /goform/SetSambaConf. La manipulación del argumento samba_userNameSda conduce a un desbordamiento de búfer. Es posible iniciar el ataque de forma remota. El exploit está disponible públicamente y… | |
| Analizada | Alta (7.4) | 0.66% | — | Tenda Ch22 Firmware | 2/9/2025 | 25/9/2026 | Se determinó una vulnerabilidad en Tenda CH22 1.0.0.1. Esta vulnerabilidad afecta a la función formexeCommand del archivo /goform/exeCommand. La manipulación del argumento cmdinput puede conducir a un desbordamiento de búfer. El ataque puede realizarse de forma remota. El exploit ha sido divulgado públicamente y puede… | |
| Analizada | Baja (0.9) | 0.16% | — | Tenda F1202 Firmware | 1/9/2025 | 30/9/2026 | Una vulnerabilidad se determinó en Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Afectada es una función desconocida del archivo /etc_ro/shadow del componente Interfaz Administrativa. Esta manipulación con la entrada Fireitup causa credenciales codificadas de forma rígida. El ataque solo puede ser ejecutado localmente. Un… |