Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.77% | — | Tenda AX3 Firmware | 3/3/2026 | 17/6/2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution. | |
| Analizada | Crítica (9.8) | 1.1% | — | Tenda AX3 Firmware | 22/1/2026 | 17/6/2026 | Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution. | |
| Analizada | Crítica (9.8) | 0.79% | — | Tenda AX3 Firmware | 21/1/2026 | 17/6/2026 | Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution. | |
| Analizada | Crítica (9.8) | 0.91% | — | Tenda AX3 Firmware | 21/1/2026 | 17/6/2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution. | |
| Analizada | Crítica (9.8) | 0.91% | — | Tenda AX3 Firmware | 21/1/2026 | 17/6/2026 | Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote code execution. | |
| Analizada | Alta (7.5) | 0.45% | — | Tenda AX3 Firmware | 13/1/2026 | 17/6/2026 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.45% | — | Tenda AX3 Firmware | 13/1/2026 | 17/6/2026 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.45% | — | Tenda AX3 Firmware | 13/1/2026 | 17/6/2026 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.45% | — | Tenda AX3 Firmware | 13/1/2026 | 17/6/2026 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.45% | — | Tenda AX3 Firmware | 13/1/2026 | 17/6/2026 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the mac2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Media (6.5) | 0.55% | — | Tenda AX3 Firmware | 8/12/2025 | 17/6/2026 | Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corruption and enable remote code execution (RCE). | |
| Analizada | Alta (7.5) | 0.37% | — | Tenda AX3 Firmware | 10/11/2025 | 17/6/2026 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.38% | — | Tenda AX3 Firmware | 10/11/2025 | 17/6/2026 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Modificada | Alta (7.5) | 0.37% | — | Tenda AX3 Firmware | 10/11/2025 | 17/6/2026 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.37% | — | Tenda AX3 Firmware | 10/11/2025 | 25/9/2026 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternParameter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.40% | — | Tenda AX3 Firmware | 31/10/2025 | 17/6/2026 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Tenda AX3 Firmware | 22/8/2025 | 17/6/2026 | Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via the serverName parameter. | |
| Analizada | Alta (7.5) | 0.41% | — | Tenda AX3 Firmware | 22/8/2025 | 17/6/2026 | Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via the deviceName parameter. | |
| Analizada | Alta (7.5) | 0.41% | — | Tenda AX3 Firmware | 22/8/2025 | 17/6/2026 | Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the ntpServer parameter. | |
| Analizada | Alta (8.8) | 0.49% | — | Tenda TX9 FirmwareTenda AX3 FirmwareTenda AX9 FirmwareTenda Ax12 Firmware | 20/2/2024 | 17/6/2026 | An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tenda AX3 Firmware | 4/1/2024 | 17/6/2026 | Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList. | |
| Modificada | Crítica (9.8) | 1.5% | — | Tenda AX3 Firmware | 7/12/2023 | 17/6/2026 | Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet. | |
| Modificada | Crítica (9.8) | 0.92% | — | Tenda AX3 Firmware | 7/12/2023 | 17/6/2026 | Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name. | |
| Modificada | Alta (7.5) | 0.74% | — | Tenda AX3 Firmware | 25/8/2023 | 17/6/2026 | Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter. | |
| Modificada | Alta (8.8) | 0.90% | — | Tenda AX3 Firmware | 24/3/2023 | 17/6/2026 | Tenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg. |