Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

74 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)1.0%—Tenda M3 Firmware5/4/202624/7/2026
A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead to buffer overflow. The attack can be executed remotely. The exploit has been…
AnalizadaMedia (6.1)0.32%—Yottamaster DM2 FirmwareYottamaster DM3 FirmwareYottamaster Dm200 Firmware3/2/202617/6/2026
An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (version equal to or prior to V1.9.12), and DM200 (version equal to or prior to V1.2.23) that could be exploited by attackers to leak or tamper with the internal file system.…
AnalizadaAlta (7.4)0.74%—Tenda M3 Firmware30/12/202517/6/2026
A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
AnalizadaAlta (7.4)3.3%—Tenda M3 Firmware30/12/202517/6/2026
A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been…
ModificadaAlta (7.4)2.9%—Tenda M3 Firmware30/12/20255/10/2026
A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is possible to initiate the attack remotely.…
ModificadaAlta (7.4)0.74%—Tenda M3 Firmware30/12/20255/10/2026
A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight/smsContent/adItemUID results in…
AnalizadaAlta (7.4)0.74%—Tenda M3 Firmware30/12/20255/10/2026
A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /goform/setAdPushInfo. The manipulation of the argument mac/terminal leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly…
ModificadaAlta (7.4)0.74%—Tenda M3 Firmware30/12/20255/10/2026
A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/setVlanInfo. Executing a manipulation of the argument ID/vlan/port can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may…
ModificadaAlta (7.4)0.74%—Tenda M3 Firmware30/12/20255/10/2026
A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlan_truck_port results in heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been…
AnalizadaAlta (7.5)0.19%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer.
AnalizadaMedia (6.5)0.28%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.
AnalizadaAlta (8.1)0.23%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated cryptographic…
AnalizadaCrítica (9.8)0.98%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.
AnalizadaAlta (7.3)0.80%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.
AnalizadaAlta (7.4)0.18%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring.
AnalizadaAlta (7.4)0.18%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files.
AnalizadaBaja (2.1)0.77%—Yottamaster DM2 FirmwareYottamaster DM3 FirmwareYottamaster Dm200 Firmware8/12/20251/10/2026
A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File Upload. Performing manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The…
AnalizadaAlta (7.4)5.1%—Tenda M3 Firmware21/8/202517/6/2026
A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseData of the file /goform/getMasterPassengerAnalyseData. The manipulation of the argument Time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been…
AnalizadaAlta (7.4)1.1%—Tenda M3 Firmware21/8/202517/6/2026
A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
ModificadaCrítica (9.8)1.1%—Tenda M3 Firmware26/12/202317/6/2026
Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.
ModificadaCrítica (9.8)0.84%—Tenda M3 Firmware26/12/202317/6/2026
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.
ModificadaCrítica (9.8)13%—Tenda M3 Firmware26/12/202317/6/2026
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.
ModificadaCrítica (9.8)8.5%—Tenda M3 Firmware26/12/202317/6/2026
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.
ModificadaCrítica (9.8)0.70%—Tenda M3 Firmware26/12/202317/6/2026
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.
ModificadaCrítica (9.8)0.76%—Tenda M3 Firmware26/12/202317/6/2026
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.