Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

2279 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.87%—Tenda AC5 Firmware7/4/202317/6/2026
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formWifiBasicSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)0.87%—Tenda AC5 Firmware7/4/202317/6/2026
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)0.87%—Tenda AC5 Firmware7/4/202317/6/2026
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)0.87%—Tenda AC5 Firmware7/4/202317/6/2026
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)0.87%—Tenda AC5 Firmware7/4/202317/6/2026
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the check_param_changed function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)0.87%—Tenda AC5 Firmware7/4/202317/6/2026
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetWirelessRepeat function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)0.87%—Tenda AC5 Firmware7/4/202317/6/2026
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)0.87%—Tenda AC5 Firmware7/4/202317/6/2026
Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetSysTime function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaAlta (7.5)16%💥 PoCTenda AC6 Firmware4/4/202317/6/2026
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.
ModificadaAlta (8.8)0.90%—Tenda AX3 Firmware24/3/202317/6/2026
Tenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg.
ModificadaAlta (7.5)1.9%—Tenda G103 Firmware23/3/202317/6/2026
Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package
ModificadaCrítica (9.8)0.93%—Tenda W20e Firmware19/3/202317/6/2026
Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,
ModificadaCrítica (9.8)0.93%—Tenda W20e Firmware19/3/202317/6/2026
Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.
ModificadaCrítica (9.8)2.8%—Tenda AX3 Firmware15/3/202317/6/2026
Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.
ModificadaCrítica (9.8)0.84%—Tenda AX3 Firmware15/3/202317/6/2026
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet.
ModificadaAlta (7.5)0.90%—Tenda W15e Firmware13/3/202317/6/2026
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
ModificadaAlta (7.5)0.90%—Tenda W15e Firmware13/3/202317/6/2026
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
ModificadaCrítica (9.8)1.0%—Tenda W15e Firmware13/3/202317/6/2026
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
ModificadaAlta (7.5)0.90%—Tenda W15e Firmware13/3/202317/6/2026
Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
ModificadaCrítica (9.8)1.0%—Tenda W15e Firmware13/3/202317/6/2026
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
ModificadaAlta (7.5)11%—Tenda Ac500 Firmware27/2/202317/6/2026
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid.
ModificadaCrítica (9.8)17%💥 PoCTenda Ac500 Firmware27/2/202317/6/2026
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.
ModificadaCrítica (9.8)0.97%—Tenda Ac500 Firmware27/2/202317/6/2026
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.
ModificadaCrítica (9.8)0.97%—Tenda W30e Firmware27/2/202317/6/2026
Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.
ModificadaCrítica (9.8)2.5%—Tenda It7-lcs FirmwareTenda It7-pcs FirmwareTenda It7-prs FirmwareTenda CP3 Firmware+127/2/202317/6/2026
Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS Tenda IT7-PRS<=V2209020908.
Orbitaley — Vulnerabilidades