Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.84% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution. | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter. | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda AC7 Firmware | 19/6/2026 | 9/7/2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC7 Firmware | 27/3/2026 | 17/6/2026 | A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg of the component POST Request Handler. Executing a manipulation of the argument Time can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Alta (8.2) | 0.23% | — | Tenda AC7 Firmware | 3/2/2026 | 17/6/2026 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material. | |
| Analizada | Media (5.1) | 0.17% | — | Tenda AC7 Firmware | 3/2/2026 | 17/6/2026 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrator to perform… | |
| Analizada | Media (6.8) | 0.14% | — | Tenda AC7 Firmware | 3/2/2026 | 17/6/2026 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose sensitive information in web management responses. Administrative credentials, including the router and/or admin panel password, are included in plaintext within configuration response bodies. In addition, responses lack appropriate Cache-Control… | |
| Analizada | Media (5.1) | 0.22% | — | Tenda AC7 Firmware | 3/2/2026 | 17/6/2026 | Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser context. | |
| Analizada | Alta (7.4) | 0.87% | — | Tenda AC7 Firmware | 10/10/2025 | 17/6/2026 | A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Alta (7.4) | 0.80% | — | Tenda AC7 Firmware | 9/10/2025 | 17/6/2026 | A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQos. The manipulation of the argument enable leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Modificada | Alta (7.4) | 0.80% | — | Tenda AC7 Firmware | 9/10/2025 | 17/6/2026 | A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform/fast_setting_pppoe_set. Executing a manipulation of the argument Password can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and… | |
| Modificada | Alta (7.4) | 0.80% | — | Tenda AC7 Firmware | 9/10/2025 | 17/6/2026 | A vulnerability was found in Tenda AC7 15.03.06.44. The affected element is an unknown function of the file /goform/WifiMacFilterSet. Performing a manipulation of the argument wifi_chkHz results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC7 Firmware | 9/10/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC7 Firmware | 9/10/2025 | 17/6/2026 | A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCfg. This manipulation of the argument ddnsEn causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 3.7% | — | Tenda AC7 Firmware | 9/10/2025 | 30/9/2026 | A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of the argument lanIp results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Analizada | Alta (7.4) | 0.82% | — | Tenda AC7 FirmwareTenda Ac18 Firmware | 15/8/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCfg. The manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Alta (7.4) | 10% | — | Tenda AC7 Firmware | 22/7/2025 | 17/6/2026 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg of the component httpd. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to launch the attack… | |
| Analizada | Alta (7.4) | 0.99% | — | Tenda AC7 Firmware | 9/6/2025 | 17/6/2026 | A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Alta (7.4) | 6.8% | — | Tenda AC7 Firmware | 9/6/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. This vulnerability affects the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.7) | 1.0% | — | Tenda AC7 Firmware | 16/5/2025 | 17/6/2026 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. Affected by this vulnerability is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument reboot_time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit… | |
| Analizada | Alta (8.7) | 1.3% | — | Tenda AC7 Firmware | 16/5/2025 | 17/6/2026 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function fromSafeSetMacFilter of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (8.7) | 7.7% | — | Tenda AC7 Firmware | 7/4/2025 | 17/6/2026 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument pptp_server_start_ip/pptp_server_end_ip leads to buffer overflow. The attack may be launched remotely. The… | |
| Analizada | Crítica (9.8) | 1.1% | — | Tenda AC7 Firmware | 24/3/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function. | |
| Analizada | Crítica (9.8) | 0.54% | — | Tenda AC7 Firmware | 19/3/2025 | 17/6/2026 | Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE. |