Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2) | 8.3% | — | Tenda AC6 Firmware | 11/5/2026 | 23/7/2026 | A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Baja (2.1) | 6.5% | — | Tenda AC6 Firmware | 11/5/2026 | 23/7/2026 | A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the… | |
| Analizada | Baja (2) | 8.3% | — | Tenda AC6 Firmware | 11/5/2026 | 23/7/2026 | A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.8) | 0.39% | — | Tenda AC6 Firmware | 8/4/2026 | 25/7/2026 | Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC6 Firmware | 27/3/2026 | 17/6/2026 | A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack is possible to be carried out… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC6 Firmware | 27/3/2026 | 17/6/2026 | A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has… | |
| Analizada | Alta (7.5) | 0.46% | — | Tenda AC6 Firmware | 2/3/2026 | 17/6/2026 | An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC6 Firmware | 27/10/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC6 15.03.06.50. This issue affects some unknown processing of the file /goform/WifiGuestSet of the component HTTP Request Handler. Such manipulation of the argument shareSpeed leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been… | |
| Analizada | Alta (7.5) | 0.41% | — | Tenda AC6 Firmware | 22/10/2025 | 17/6/2026 | Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the wanMTU, wanSpeed, cloneType, mac, serviceName, serverName, wanMTU2, wanSpeed2, cloneType2, mac2, serviceName2, and serverName2 parameters. | |
| Modificada | Alta (7.5) | 0.42% | — | Tenda AC6 Firmware | 22/10/2025 | 17/6/2026 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Modificada | Alta (7.5) | 0.40% | — | Tenda AC6 Firmware | 22/10/2025 | 17/6/2026 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Modificada | Alta (7.5) | 0.41% | — | Tenda AC6 Firmware | 22/10/2025 | 17/6/2026 | Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters. | |
| Modificada | Alta (7.5) | 0.41% | — | Tenda AC6 Firmware | 22/10/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the schedStartTime and schedEndTime parameters. | |
| Modificada | Alta (7.5) | 0.41% | — | Tenda AC6 Firmware | 22/10/2025 | 17/6/2026 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Modificada | Alta (7.5) | 0.49% | — | Tenda AC6 Firmware | 22/10/2025 | 17/6/2026 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Analizada | Media (6.5) | 3.3% | — | Tenda AC6 Firmware | 19/9/2025 | 17/6/2026 | Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the list and vlanId parameters, the sub_ADBC0 helper function concatenates these user-supplied values into nvram set system… | |
| Analizada | Alta (7.7) | 0.44% | — | Tenda AC6 Firmware | 19/9/2025 | 17/6/2026 | An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of service via the funcname, funcpara1, funcpara2 parameters to the formSetCfm function (uri path: SetCfm). | |
| Analizada | Media (6.5) | 0.25% | — | Tenda AC6 Firmware | 27/8/2025 | 17/6/2026 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function. | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda AC6 Firmware | 20/8/2025 | 17/6/2026 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function. | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda AC6 Firmware | 20/8/2025 | 17/6/2026 | Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function. | |
| Analizada | Alta (7.3) | 0.28% | — | Tenda AC6 Firmware | 20/8/2025 | 17/6/2026 | Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function. | |
| Analizada | Media (6.5) | 0.26% | — | Tenda AC6 Firmware | 20/8/2025 | 17/6/2026 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function. | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda AC6 Firmware | 20/8/2025 | 17/6/2026 | Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and deviceList. | |
| Modificada | Crítica (9.8) | 0.69% | — | Tenda AC6 Firmware | 20/8/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP response can lead to arbitrary code execution. An attacker can send an HTTP response to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.30% | — | Tenda AC6 Firmware | 20/8/2025 | 17/6/2026 | A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. |