Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.55%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication.
AnalizadaAlta (8.6)0.67%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.
AnalizadaAlta (8.7)0.51%—Buffalo Wzr-s900dhp FirmwareBuffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p Firmware+4227/3/202617/6/2026
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without authentication.
AnalizadaAlta (8.7)0.48%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products.
AnalizadaAlta (8.6)1.4%—Buffalo Wcr-1166dhpl FirmwareBuffalo Wsr3600be4-kh FirmwareBuffalo Wsr3600be4p FirmwareBuffalo Wxr-1750dhp Firmware+4227/3/202617/6/2026
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.
AnalizadaMedia (6.5)0.82%—Tenda Ax12 Firmware20/3/202517/6/2026
Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList.
AnalizadaAlta (7.5)0.56%—Tenda Ax12 Firmware20/3/202517/6/2026
Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.
AnalizadaAlta (8)1.5%—Tenda AX9 FirmwareTenda Ax12 Firmware19/7/202417/6/2026
AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.
AnalizadaMedia (6.5)0.40%—Tenda Ax12 Firmware16/7/202417/6/2026
An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packet handling.
AnalizadaMedia (6.8)0.34%—Tenda Ax12 Firmware10/7/202417/6/2026
Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function.
AnalizadaCrítica (9.8)0.82%—Tenda Ax12 Firmware14/3/202417/6/2026
Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.
AnalizadaAlta (8.8)0.49%—Tenda TX9 FirmwareTenda AX3 FirmwareTenda AX9 FirmwareTenda Ax12 Firmware20/2/202417/6/2026
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
ModificadaAlta (7.5)0.62%—Tenda Ax12 Firmware10/1/202417/6/2026
Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.
ModificadaCrítica (9.8)2.4%—Tenda Ax12 Firmware7/12/202317/6/2026
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
ModificadaCrítica (9.8)2.5%—Tenda Ax12 Firmware7/12/202317/6/2026
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
ModificadaCrítica (9.8)0.92%—Tenda Ax12 Firmware7/12/202317/6/2026
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
ModificadaCrítica (9.8)0.92%—Tenda Ax12 Firmware7/12/202317/6/2026
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .
ModificadaCrítica (9.8)0.92%—Tenda Ax12 Firmware7/12/202317/6/2026
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
ModificadaCrítica (9.8)1.1%—Tenda Ax12 Firmware5/1/202317/6/2026
There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not to restart or even execute arbitrary code. It is a different vulnerability from CVE-2022-2414.
ModificadaAlta (8.8)7.5%—Tenda Ax12 Firmware12/12/202217/6/2026
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
ModificadaAlta (7.5)0.82%—Tenda Ax12 Firmware12/12/202217/6/2026
Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wifi_set .
ModificadaAlta (8.8)2.1%—Tenda Ax12 Firmware12/12/202217/6/2026
Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.
ModificadaAlta (8.8)2.2%—Tenda Ax12 Firmware12/12/202217/6/2026
Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.
ModificadaAlta (8.8)0.35%—Buffalo Wcr-300 FirmwareBuffalo Whr-hp-g300n FirmwareBuffalo Whr-hp-gn FirmwareBuffalo Wpl-05g300 Firmware+717/12/202217/6/2026
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and…
ModificadaMedia (5.5)0.30%—Tenda Ax12 Firmware25/8/202217/6/2026
Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, which satisfies the request of the upper-level interface function sub_430124, that is, handles the post request under /goform/SetIpMacBind.