Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.64% | — | Tenda HG7AITenda HG9AITenda Hg10AI | 2/10/2026 | 2/10/2026 | A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The… | |
| Aplazada | Alta (8.6) | 2.7% | — | Tenda Hg10AIBOAAI | 6/9/2026 | 8/9/2026 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Hg10AIBOA WEB ServerAI | 6/9/2026 | 11/9/2026 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly… | |
| Aplazada | Alta (8.9) | 1.1% | — | Tenda Hg10AI | 6/9/2026 | 8/9/2026 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Hg10AIBOA WEB ServerAI | 3/9/2026 | 3/9/2026 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might… | |
| Aplazada | Alta (8.9) | 1.1% | — | Tenda Hg10AIBOA WEB ServerAI | 3/9/2026 | 3/9/2026 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Tenda Hg10AIBOA WEB ServerAI | 30/8/2026 | 1/9/2026 | A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Alta (7.4) | 0.48% | — | Tenda Hg7hg9AITenda Hg10AI | 8/6/2026 | 2/10/2026 | A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Crítica (9.3) | 6.6% | — | Tenda Hg7hg9AITenda Hg10AI | 8/6/2026 | 2/10/2026 | A vulnerability was determined in Tenda HG7, HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow. The attack may be performed from remote. | |
| Aplazada | Alta (8.7) | 3.8% | — | Tenda Hg7hg9AITenda Hg10AI | 8/6/2026 | 2/10/2026 | A vulnerability was found in Tenda HG7, HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_OtherSet of the file /boaform/voip_other_set of the component Web Management Interface. Performing a manipulation of the argument funckey_transfer results in stack-based buffer overflow. The attack… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda Hg10 Firmware | 25/4/2026 | 17/6/2026 | A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon. This issue affects the function formRoute of the file /boaform/formRouting of the component Boa Service. This manipulation of the argument nextHop causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published… | |
| Analizada | Baja (2) | 4.7% | — | Tenda Hg10 Firmware | 30/1/2026 | 17/6/2026 | A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /boaform/formSysCmd. This manipulation of the argument sysCmd causes command injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 3.1% | — | Tenda Hg10 Firmware | 30/1/2026 | 17/6/2026 | A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the file /boaform/admin/formLogin of the component Login Interface. The manipulation of the argument Host results in command injection. The attack can be launched remotely. The… | |
| Analizada | Media (5.5) | 3.2% | — | Tenda Hg10 Firmware | 30/1/2026 | 17/6/2026 | A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the file /boaform/formSamba of the component Boa Webserver. Executing a manipulation of the argument serverString can lead to command injection. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Alta (8.6) | 1.2% | — | Ncp-hg100AI | 14/11/2025 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS command with root… | |
| Modificada | Alta (7.5) | 1.3% | — | Asus Hg100 FirmwareAsus Mw100 FirmwareAsus Ws-101 FirmwareAsus Ts-101 Firmware+3 | 20/12/2019 | 17/6/2026 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks. | |
| Modificada | Crítica (9.8) | 0.84% | — | Asus Hg100 FirmwareAsus Mw100 FirmwareAsus Ws-101 FirmwareAsus Ts-101 Firmware+3 | 20/12/2019 | 17/6/2026 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages. | |
| Modificada | Alta (7.5) | 1.3% | — | Asus Hg100 FirmwareAsus Mw100 FirmwareAsus Ws-101 FirmwareAsus Ts-101 Firmware+3 | 20/12/2019 | 17/6/2026 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack. | |
| Modificada | Alta (8.1) | 4.0% | — | Asus Hg100 Firmware | 29/8/2019 | 17/6/2026 | A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability… | |
| Modificada | Alta (7.5) | 3.0% | — | Asus Hg100 Firmware | 29/8/2019 | 17/6/2026 | The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections and associated resources alive for a long period of time. CVSS 3.0 Base score… | |
| Modificada | Alta (7.5) | 11% | — | Asus Hg100 Firmware | 10/8/2018 | 17/6/2026 | ASUS HG100 devices allow denial of service via an IPv4 packet flood. | |
| Modificada | Crítica (9.8) | 6.7% | — | Asus Hg100 Firmware | 25/7/2018 | 17/6/2026 | ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution. | |
| Modificada | Crítica (9.8) | 10% | — | Humaxdigital Hg100r Firmware | 19/7/2017 | 17/6/2026 | The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to expose the management console. The router is not validating the session token while returning answers… | |
| Modificada | Crítica (9.8) | 2.2% | — | Humaxdigital Hg100r Firmware | 4/7/2017 | 17/6/2026 | An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin. | |
| Modificada | Media (6.1) | 0.76% | — | Humaxdigital Hg100r Firmware | 4/7/2017 | 17/6/2026 | An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page. |