Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.92% | — | HP W3z72e FirmwareHP W3z72f FirmwareHP W3z72g FirmwareHP W3z72h Firmware+69 | 25/7/2025 | 17/6/2026 | Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauthenticated users to view sensitive print job information. | |
| Modificada | Crítica (9.8) | 0.64% | — | Tenda W18e Firmware | 28/5/2025 | 5/7/2026 | An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules route. | |
| Analizada | Media (5.3) | 0.58% | — | Tenda W18e Firmware | 4/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is the function formSetAccountList of the file /goform/setModules. The manipulation of the argument Password leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.50% | — | Tenda W18e Firmware | 20/3/2025 | 17/6/2026 | Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Modificada | Media (6.5) | 0.50% | — | Tenda W18e Firmware | 20/3/2025 | 5/7/2026 | Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (6.5) | 1.2% | — | Tenda W18e Firmware | 10/2/2025 | 17/6/2026 | A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, including WiFi SSID, WiFi password, and base64-encoded administrator credentials, by sending a specially crafted HTTP POST… | |
| Analizada | Alta (8.3) | 0.46% | — | Tenda W18e Firmware | 10/2/2025 | 17/6/2026 | Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service. | |
| Analizada | Alta (8) | 0.83% | — | Tenda W18e Firmware | 10/2/2025 | 17/6/2026 | A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. This vulnerability occurs due to improper input validation when handling user-supplied data in the delFacebookPic function. | |
| Analizada | Alta (8.8) | 0.91% | — | Tenda W18e Firmware | 10/2/2025 | 17/6/2026 | Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP request. | |
| Analizada | Alta (8.8) | 0.54% | — | Tenda W18e Firmware | 10/2/2025 | 17/6/2026 | A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges. | |
| Analizada | Alta (8.8) | 0.64% | — | Tenda W18e Firmware | 10/2/2025 | 17/6/2026 | Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized changes to WiFi configuration settings and administrative credentials. | |
| Analizada | Alta (8) | 0.47% | — | Tenda W18e Firmware | 10/2/2025 | 17/6/2026 | Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted data to the delWewifiPic function. | |
| Analizada | Media (6.5) | 0.84% | — | Tenda W18e Firmware | 10/2/2025 | 17/6/2026 | Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the administrator password by sending a specially crafted HTTP POST request to the setLoginPassword function, bypassing the… | |
| Analizada | Alta (8.8) | 0.59% | — | Tenda W18e Firmware | 10/2/2025 | 17/6/2026 | A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges. | |
| Modificada | Crítica (9.8) | 18% | — | Tenda W18e Firmware | 25/10/2023 | 17/6/2026 | Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function. | |
| Modificada | Crítica (9.8) | 0.90% | — | Tenda W18e Firmware | 25/10/2023 | 17/6/2026 | Tenda W18E V16.01.0.8(1576) contains a stack overflow vulnerability via the portMirrorMirroredPorts parameter in the formSetNetCheckTools function. | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+2696 | 12/12/2022 | 17/6/2026 | Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR. |