Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Tenda Ac18 Firmware | 27/4/2026 | 17/6/2026 | A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands. | |
| Analizada | Alta (7.4) | 0.78% | — | Tenda Ac18 Firmware | 21/12/2025 | 28/9/2026 | A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the component HTTP Request Handler. The manipulation of the argument scanList results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be… | |
| Analizada | Alta (7.4) | 0.74% | — | Tenda Ac18 Firmware | 21/12/2025 | 17/6/2026 | A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the file /goform/GetParentControlInfo of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The… | |
| Modificada | Alta (8.8) | 0.65% | — | Tenda Ac18 Firmware | 10/11/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service… | |
| Modificada | Media (5.4) | 0.22% | — | Tenda Ac18 Firmware | 10/11/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage. | |
| Analizada | Alta (7.4) | 1.1% | — | Tenda Ac18 Firmware | 6/10/2025 | 17/6/2026 | A vulnerability was detected in Tenda AC18 15.03.05.19(6318). This issue affects some unknown processing of the file /goform/SetDDNSCfg. The manipulation of the argument ddnsEn results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Analizada | Alta (7.4) | 1.2% | — | Tenda Ac18 Firmware | 6/10/2025 | 17/6/2026 | A security vulnerability has been detected in Tenda AC18 15.03.05.19(6318). This vulnerability affects unknown code of the file /goform/SetUpnpCfg. The manipulation of the argument upnpEn leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and… | |
| Modificada | Alta (7.4) | 1.2% | — | Tenda Ac18 Firmware | 6/10/2025 | 17/6/2026 | A weakness has been identified in Tenda AC18 15.03.05.19(6318). This affects an unknown part of the file /goform/WifiMacFilterSet. Executing a manipulation of the argument wifi_chkHz can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and… | |
| Modificada | Alta (7.4) | 0.80% | — | Tenda Ac18 Firmware | 6/10/2025 | 17/6/2026 | A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionality of the file /goform/fast_setting_pppoe_set. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.83% | — | Tenda Ac18 Firmware | 6/10/2025 | 17/6/2026 | A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionality of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and… | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda Ac18 Firmware | 2/10/2025 | 17/6/2026 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function. | |
| Analizada | Media (5.3) | 0.42% | — | Tenda Ac18 Firmware | 2/10/2025 | 17/6/2026 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda Ac18 Firmware | 2/10/2025 | 17/6/2026 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function. | |
| Analizada | Alta (7.5) | 0.49% | — | Tenda Ac18 Firmware | 2/10/2025 | 17/6/2026 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function. | |
| Analizada | Alta (7.4) | 0.80% | — | Tenda Ac18 Firmware | 28/9/2025 | 17/6/2026 | A flaw has been found in Tenda AC18 15.03.05.19. This impacts an unknown function of the file /goform/saveAutoQos. This manipulation of the argument enable causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 3.7% | — | Tenda Ac18 Firmware | 28/9/2025 | 17/6/2026 | A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. The manipulation of the argument lanIp leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Alta (7.4) | 3.7% | — | Tenda Ac18 Firmware | 28/9/2025 | 17/6/2026 | A weakness has been identified in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the file /goform/SetServerConfig. Executing manipulation can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be… | |
| Analizada | Alta (7.4) | 0.80% | — | Tenda Ac18 Firmware | 28/9/2025 | 30/9/2026 | A vulnerability was detected in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. | |
| Analizada | Alta (7.4) | 0.82% | — | Tenda AC7 FirmwareTenda Ac18 Firmware | 15/8/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCfg. The manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Baja (2.9) | 0.44% | — | Tenda Ac18 Firmware | 26/7/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component Samba. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high.… | |
| Analizada | Alta (8.7) | 0.96% | — | Tenda Ac18 Firmware | 4/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.7) | 0.96% | — | Tenda Ac18 Firmware | 4/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formsetreboottimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.7) | 0.96% | — | Tenda Ac18 Firmware | 4/6/2025 | 17/6/2026 | A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 3.4% | — | Tenda Ac18 Firmware | 4/6/2025 | 17/6/2026 | A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetIptv of the file /goform/SetIPTVCfg. The manipulation of the argument list leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (8.6) | 5.9% | — | Tenda AC8 FirmwareTenda Ac10 FirmwareTenda Ac18 Firmware | 17/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit… |