Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formWifiBasicSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the check_param_changed function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetWirelessRepeat function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 0.87% | — | Tenda AC5 Firmware | 7/4/2023 | 17/6/2026 | Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the fromSetSysTime function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Alta (7.5) | 16% | 💥 PoC | Tenda AC6 Firmware | 4/4/2023 | 17/6/2026 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function. | |
| Modificada | Alta (8.8) | 0.90% | — | Tenda AX3 Firmware | 24/3/2023 | 17/6/2026 | Tenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg. | |
| Modificada | Alta (7.5) | 1.9% | — | Tenda G103 Firmware | 23/3/2023 | 17/6/2026 | Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package | |
| Modificada | Crítica (9.8) | 0.93% | — | Tenda W20e Firmware | 19/3/2023 | 17/6/2026 | Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime, | |
| Modificada | Crítica (9.8) | 0.93% | — | Tenda W20e Firmware | 19/3/2023 | 17/6/2026 | Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify. | |
| Modificada | Crítica (9.8) | 2.8% | — | Tenda AX3 Firmware | 15/3/2023 | 17/6/2026 | Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AX3 Firmware | 15/3/2023 | 17/6/2026 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet. | |
| Modificada | Alta (7.5) | 0.90% | — | Tenda W15e Firmware | 13/3/2023 | 17/6/2026 | Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelWewifiPi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Modificada | Alta (7.5) | 0.90% | — | Tenda W15e Firmware | 13/3/2023 | 17/6/2026 | Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Modificada | Crítica (9.8) | 1.0% | — | Tenda W15e Firmware | 13/3/2023 | 17/6/2026 | Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Modificada | Alta (7.5) | 0.90% | — | Tenda W15e Firmware | 13/3/2023 | 17/6/2026 | Tenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Modificada | Crítica (9.8) | 1.0% | — | Tenda W15e Firmware | 13/3/2023 | 17/6/2026 | Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Modificada | Alta (7.5) | 11% | — | Tenda Ac500 Firmware | 27/2/2023 | 17/6/2026 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid. | |
| Modificada | Crítica (9.8) | 17% | 💥 PoC | Tenda Ac500 Firmware | 27/2/2023 | 17/6/2026 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface. | |
| Modificada | Crítica (9.8) | 0.97% | — | Tenda Ac500 Firmware | 27/2/2023 | 17/6/2026 | Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface. | |
| Modificada | Crítica (9.8) | 0.97% | — | Tenda W30e Firmware | 27/2/2023 | 17/6/2026 | Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface. | |
| Modificada | Crítica (9.8) | 2.5% | — | Tenda It7-lcs FirmwareTenda It7-pcs FirmwareTenda It7-prs FirmwareTenda CP3 Firmware+1 | 27/2/2023 | 17/6/2026 | Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS Tenda IT7-PRS<=V2209020908. |