Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.85% | — | Tenda W20eAI | 14/9/2026 | 14/9/2026 | A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely. | |
| Aplazada | Alta (7.1) | 0.71% | — | Tenda W20eAI | 14/9/2026 | 15/9/2026 | A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overflow. It is possible to launch the attack remotely. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Tenda W20eAI | 17/8/2026 | 9/9/2026 | Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819 | |
| Aplazada | Crítica (9.8) | 0.59% | — | Tenda W20eAI | 17/8/2026 | 31/8/2026 | Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access. | |
| Aplazada | Crítica (9.8) | 0.86% | — | Tneda W20eAI | 17/8/2026 | 31/8/2026 | An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda W20eAI | 14/8/2026 | 14/8/2026 | A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda W20eAI | 14/8/2026 | 18/8/2026 | A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda W20eAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of the component QoS Edit. Such manipulation of the argument qosListConnecttedNum leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is… | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Shenzhen Tenda Technology W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 20/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMACAddr parameter of the fromSetDhcpRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.55% | — | Tenda W20eAI | 9/6/2026 | 23/7/2026 | Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Aplazada | Alta (7.4) | 0.47% | — | Tenda W20eAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The manipulation of the argument wifiFilterListRemark leads to stack-based buffer overflow. The attack may be initiated remotely.… | |
| Aplazada | Alta (7.4) | 0.47% | — | Tenda W20eAI | 8/6/2026 | 23/7/2026 | A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.47% | — | Tenda W20eAI | 8/6/2026 | 23/7/2026 | A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public… | |
| Modificada | Crítica (9.8) | 0.55% | — | Tenda W20e Firmware | 2/3/2026 | 17/6/2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addWewifiWhiteUser` function and processed by `sscanf` without size validation, it could lead to a buffer overflow vulnerability. | |
| Analizada | Crítica (9.8) | 0.43% | — | Tenda W20e Firmware | 2/3/2026 | 17/6/2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule` function and are processed by `ret = sscanf(pRule, " %d\t%[^\t]\t%[^\n\r\t]", &dhcpsIndex, dhcpsIP, dhcpsMac);`, the lack of size validation for the rules could lead to… | |
| Modificada | Crítica (9.8) | 0.71% | — | Tenda W20e Firmware | 2/3/2026 | 17/6/2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before concatenating them into `gstruleQos` may lead to buffer overflow. | |
| Modificada | Crítica (9.8) | 0.64% | — | Tenda W20e Firmware | 2/3/2026 | 17/6/2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`. | |
| Modificada | Crítica (9.8) | 0.66% | — | Tenda W20e Firmware | 2/3/2026 | 17/6/2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using `sprintf` without proper size validation, it could lead to a buffer overflow vulnerability. | |
| Modificada | Crítica (9.8) | 0.66% | — | Tenda W20e Firmware | 2/3/2026 | 17/6/2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addAuthUser` function and processed by `sscanf` without size validation, it could lead to buffer overflow. | |
| Modificada | Crítica (9.8) | 0.66% | — | Tenda W20e Firmware | 2/3/2026 | 17/6/2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this value is used in `sprintf` without validating variable sizes, it could lead to a buffer overflow vulnerability. | |
| Analizada | Crítica (9.8) | 0.66% | — | Tenda W20e Firmware | 2/3/2026 | 17/6/2026 | An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value is passed into the `getMibPrefix` function and concatenated using `sprintf` without proper size validation, it could lead to a buffer overflow vulnerability. |