Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.80% | — | Tenda O3 Firmware1.0.0.10(2478) | 27/10/2025 | 17/6/2026 | A vulnerability was detected in Tenda O3 1.0.0.10(2478). This issue affects the function SetValue/GetValue of the file /goform/sysAutoReboot. Performing a manipulation of the argument enable results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Alta (7.4) | 0.80% | — | Tenda O3 Firmware1.0.0.10(2478) | 27/10/2025 | 17/6/2026 | A security vulnerability has been detected in Tenda O3 1.0.0.10(2478). This vulnerability affects the function SetValue/GetValue of the file /goform/setVlanConfig. Such manipulation of the argument lan leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly… | |
| Modificada | Alta (7.4) | 0.80% | — | Tenda O3 Firmware1.0.0.10(2478) | 27/10/2025 | 17/6/2026 | A weakness has been identified in Tenda O3 1.0.0.10(2478). This affects the function SetValue/GetValue of the file /goform/setNetworkService. This manipulation of the argument upnpEn causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Modificada | Alta (7.4) | 0.84% | — | Tenda O3 Firmware1.0.0.10(2478) | 27/10/2025 | 17/6/2026 | A security flaw has been discovered in Tenda O3 1.0.0.10(2478). Affected by this issue is the function SetValue/GetValue of the file /goform/setDmzInfo. The manipulation of the argument dmzIP results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the… | |
| Modificada | Alta (7.4) | 1.0% | — | Tenda O3 Firmware1.0.0.10(2478) | 27/10/2025 | 17/6/2026 | A vulnerability was determined in Tenda O3 1.0.0.10(2478). Affected is the function SetValue/GetValue of the file /goform/setDhcpConfig. Executing a manipulation of the argument dhcpEn can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be… | |
| Modificada | Alta (7.4) | 1.1% | — | Tenda O3 Firmware1.0.0.10(2478) | 27/10/2025 | 30/9/2026 | A vulnerability was identified in Tenda O3 1.0.0.10(2478). Affected by this vulnerability is the function SetValue/GetValue of the file /goform/AdvSetLanip. The manipulation of the argument lanIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and… | |
| Analizada | Crítica (9.8) | 0.56% | — | Tenda O3 Firmware | 22/8/2025 | 17/6/2026 | Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter. | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda O3 Firmware | 11/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). Affected by this vulnerability is the function formWifiMacFilterSet of the file /goform/setWrlFilterList of the component httpd. The manipulation of the argument macList leads to stack-based buffer overflow. The attack can be launched… | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda O3 Firmware | 11/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Tenda O3V2 1.0.0.12(3880). Affected is the function setAutoReboot of the file /goform/setNetworkService of the component httpd. The manipulation of the argument week leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda O3 Firmware | 11/7/2025 | 17/6/2026 | A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been rated as critical. This issue affects the function fromMacFilterModify of the file /goform/operateMacFilter of the component httpd. The manipulation of the argument mac leads to stack-based buffer overflow. The attack may be initiated remotely. The… | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda O3 Firmware | 11/7/2025 | 17/6/2026 | A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been declared as critical. This vulnerability affects the function formWifiBasicSet of the file /goform/setWrlBasicInfo of the component httpd. The manipulation of the argument extChannel leads to stack-based buffer overflow. The attack can be initiated… | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda O3 Firmware | 10/7/2025 | 17/6/2026 | A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fromSpeedTestSet of the file /goform/setRateTest of the component httpd. The manipulation of the argument destIP leads to stack-based buffer overflow. It is possible to initiate the attack remotely.… | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda O3 Firmware | 10/7/2025 | 17/6/2026 | A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the function fromPingResultGet of the file /goform/setPing of the component httpd. The manipulation of the argument destIP leads to stack-based buffer overflow. The attack may be launched remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda O3 Firmware | 10/7/2025 | 17/6/2026 | A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability is the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be launched remotely.… | |
| Analizada | Alta (7.4) | 0.89% | — | Tenda O3 Firmware | 10/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function fromSysToolTime of the file /goform/setSysTimeInfo of the component httpd. The manipulation of the argument Time leads to stack-based buffer overflow. It is possible to launch the attack remotely. The… | |
| Analizada | Baja (2.1) | 3.4% | — | Tenda O3 Firmware | 10/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of the component httpd. The manipulation of the argument dest leads to command injection. The attack may be initiated remotely. The exploit… | |
| Analizada | Baja (2.1) | 13% | — | Tenda O3 Firmware | 10/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument domain leads to os command injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.43% | — | Tenda O3 Firmware | 6/11/2024 | 17/6/2026 | Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed format to a router running the corresponding version of the firmware. | |
| Modificada | Alta (8.7) | 1.3% | — | Tenda O3 Firmware | 27/7/2024 | 17/6/2026 | A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation of the argument time leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.7) | 1.1% | — | Tenda O3 Firmware | 27/7/2024 | 17/6/2026 | A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been declared as critical. This vulnerability affects the function fromMacFilterSet of the file /goform/setMacFilter. The manipulation of the argument remark leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.7) | 1.3% | — | Tenda O3 Firmware1.0.0.10(2478) | 22/7/2024 | 17/6/2026 | A vulnerability has been found in Tenda O3 1.0.0.10 and classified as critical. Affected by this vulnerability is the function fromVirtualSet. The manipulation of the argument ip/localPort/publicPort/app leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.7) | 1.2% | — | Tenda O3 Firmware1.0.0.10(2478) | 22/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tenda O3 1.0.0.10. Affected is the function fromDhcpSetSer. The manipulation of the argument dhcpEn/startIP/endIP/preDNS/altDNS/mask/gateway leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Alta (8.7) | 1.3% | — | Tenda O3 Firmware1.0.0.10(2478) | 22/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Tenda O3 1.0.0.10. This issue affects the function formexeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (8.7) | 1.2% | — | Tenda O3 Firmware1.0.0.10(2478) | 22/7/2024 | 17/6/2026 | A vulnerability classified as critical was found in Tenda O3 1.0.0.10. This vulnerability affects the function formQosSet. The manipulation of the argument remark/ipRange/upSpeed/downSpeed/enable leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.8) | 2.0% | — | Tenda O3 Firmware | 4/6/2024 | 17/6/2026 | Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges. |