Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the manualTime parameter.
ModificadaCrítica (9.8)3.0%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.
ModificadaAlta (7.5)1.2%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetVirtualSer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsHijackRule parameter.
ModificadaAlta (7.5)1.1%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
ModificadaAlta (7.5)1.2%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allows attackers to cause a Denial of Service (DoS) via the portMappingServer, portMappingProtocol, portMappingWan, porMappingtInternal, and portMappingExternal parameters.
ModificadaAlta (7.5)1.1%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetStaticRoute. This vulnerability allows attackers to cause a Denial of Service (DoS) via the staticRouteNet, staticRouteMask, and staticRouteGateway parameters.
ModificadaAlta (7.5)1.1%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formDelDhcpRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the delDhcpIndex parameter.
ModificadaAlta (7.5)1.1%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindModify. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IPMacBindRuleIP and IPMacBindRuleMac parameters.
ModificadaAlta (7.5)1.1%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetQvlanList. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qvlanName parameter.
ModificadaAlta (7.5)1.1%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddVpnUsers. This vulnerability allows attackers to cause a Denial of Service (DoS) via the vpnUsers parameter.
ModificadaCrítica (9.8)1.9%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.
ModificadaAlta (7.5)1.1%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function guestWifiRuleRefresh. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qosGuestUpstream and qosGuestDownstream parameters.
ModificadaAlta (7.5)1.1%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDnsForward. This vulnerability allows attackers to cause a Denial of Service (DoS) via the DnsForwardRule parameter.
ModificadaCrítica (9.8)1.9%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.
ModificadaCrítica (9.8)1.9%—Tendacn G1 FirmwareTendacn G3 Firmware4/2/202217/6/2026
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.
ModificadaMedia (6.7)0.33%—Intel SGX SDKIntel Xeon Gold 6342 FirmwareIntel Xeon Gold 6346 FirmwareIntel Xeon Gold 6330 Firmware+17917/11/202117/6/2026
Improper input validation in the Intel(R) SGX SDK applications compiled for SGX2 enabled processors may allow a privileged user to potentially escalation of privilege via local access.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitHikvision Ds-2cd2026g2-iu/sl FirmwareHikvision Ds-2cd2046g2-iu/sl FirmwareHikvision Ds-2cd2066g2-i(u) FirmwareHikvision Ds-2cd2066g2-iu/sl Firmware+25222/9/202117/6/2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
ModificadaCrítica (9.8)3.2%—Tendacn G1 FirmwareTendacn G3 Firmware16/4/202117/6/2026
Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted "action/umountUSBPartition" request. This occurs because the "formSetUSBPartitionUmount" function executes the "doSystemCmd" function…
ModificadaCrítica (9.8)25%—Tendacn G0 FirmwareTendacn G1 FirmwareTendacn G3 Firmware16/4/202117/6/2026
Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs…
ModificadaCrítica (9.8)2.8%—Tenda G1 FirmwareTenda G3 Firmware14/4/202117/6/2026
Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.
ModificadaCrítica (9.8)2.8%—Tenda G1 FirmwareTenda G3 Firmware14/4/202117/6/2026
Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the parameter "IPMacBindIndex" to strcpy without limit.
ModificadaCrítica (9.8)2.9%—Tenda G1 FirmwareTenda G3 Firmware14/4/202117/6/2026
Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"qosIndex "request. This occurs because the "formQOSRuleDel" function directly passes the parameter "qosIndex" to strcpy without limit.
ModificadaAlta (7.8)0.33%—Vsolcn V1600d FirmwareVsolcn V1600g1 FirmwareVsolcn V1600g2 Firmware29/11/202017/6/2026
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. A hardcoded RSA private key (specific to V1600D, V1600G1, and V1600G2) is contained in the firmware images.
ModificadaCrítica (9.8)2.4%—Vsolcn V1600d FirmwareVsolcn V1600d4l FirmwareVsolcn V1600d-mini FirmwareVsolcn V1600g1 Firmware+129/11/202017/6/2026
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. Command injection can occur in "upload tftp syslog" and "upload tftp configuration" in the CLI via a crafted filename.
ModificadaMedia (5.9)0.48%—Vsolcn V1600d FirmwareVsolcn V1600d4l FirmwareVsolcn V1600d-mini FirmwareVsolcn V1600g1 Firmware+129/11/202017/6/2026
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH is not always available. An attacker can intercept passwords sent in cleartext and conduct a man-in-the-middle attack…