Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.85% | — | Tenda Ac1206 FirmwareTenda AC5 FirmwareTenda AC9 FirmwareTenda AC8 Firmware+1 | 7/8/2023 | 17/6/2026 | Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda Ac10 FirmwareTenda Ac1206 FirmwareTenda AC6 FirmwareTenda AC7 Firmware+5 | 7/8/2023 | 17/6/2026 | Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC7 FirmwareTenda F1203 FirmwareTenda Fh1205 FirmwareTenda AC5 Firmware+1 | 7/8/2023 | 17/6/2026 | Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function. | |
| Modificada | Crítica (9.8) | 0.93% | — | Tenda F1202 FirmwareTenda Fh1202 FirmwareTenda Ac10 FirmwareTenda Ac1206 Firmware+3 | 14/7/2023 | 17/6/2026 | Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient. | |
| Modificada | Crítica (9.8) | 0.93% | — | Tenda F1202 FirmwareTenda Fh1202 FirmwareTenda Ac10 FirmwareTenda Ac1206 Firmware+3 | 14/7/2023 | 17/6/2026 | Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting. | |
| Modificada | Media (4.9) | 0.51% | — | Dell Idrac9 Firmware | 18/1/2023 | 17/6/2026 | Dell iDRAC9 version 6.00.02.00 and prior contain an improper input validation vulnerability in Racadm when the firmware lock-down configuration is set. A remote high privileged attacker could exploit this vulnerability to bypass the firmware lock-down configuration and perform a firmware update. | |
| Modificada | Alta (7.2) | 1.1% | — | Tenda AC9 Firmware | 31/8/2022 | 17/6/2026 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting. | |
| Modificada | Alta (7.2) | 1.1% | — | Tenda AC9 Firmware | 31/8/2022 | 17/6/2026 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg. | |
| Modificada | Alta (8.8) | 1.1% | — | Tenda AC9 Firmware | 31/8/2022 | 17/6/2026 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg. | |
| Modificada | Alta (8.8) | 1.1% | — | Tenda AC9 Firmware | 31/8/2022 | 17/6/2026 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList. | |
| Modificada | Media (5.5) | 0.25% | — | Tendacn AC9 Firmware | 19/8/2022 | 9/7/2026 | Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd. | |
| Modificada | Crítica (9.8) | 2.4% | — | Tenda AC9 Firmware | 16/8/2022 | 17/6/2026 | Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg. | |
| Modificada | Media (6.5) | 0.81% | — | Tenda AC9 Firmware | 24/5/2022 | 17/6/2026 | There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long list parameter occurs. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 3/5/2022 | 17/6/2026 | There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 7/4/2022 | 17/6/2026 | There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn. The attacker can obtain a stable root shell through a constructed payload. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 7/4/2022 | 17/6/2026 | There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21_cn. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 28/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function. | |
| Modificada | Crítica (9.8) | 4.9% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter in the SetIPTVCfg function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function. | |
| Modificada | Crítica (9.8) | 4.9% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg function. | |
| Modificada | Crítica (9.8) | 9.1% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda AC9 Firmware | 18/3/2022 | 17/6/2026 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo function. |