Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

149 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)4.4%—Tenda HG3 Firmware27/4/202617/6/2026
A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
AnalizadaAlta (7.4)1.0%—Tenda HG3 Firmware27/4/202617/6/2026
A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaAlta (7.4)4.4%—Tenda HG3 Firmware27/4/202617/6/2026
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
AnalizadaAlta (7.4)4.4%—Tenda HG3 Firmware27/4/202617/6/2026
A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_loid results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the…
AnalizadaAlta (7.5)0.19%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer.
AnalizadaMedia (6.5)0.28%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.
AnalizadaAlta (8.1)0.23%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated cryptographic…
AnalizadaCrítica (9.8)0.98%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.
AnalizadaMedia (6.6)1.1%—Aqara Camera HUB G3 Firmware10/12/202525/9/2026
Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with root privileges through malicious QR codes during device setup and factory reset.
AnalizadaAlta (7.3)0.80%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names.
AnalizadaAlta (7.4)0.18%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring.
AnalizadaAlta (7.4)0.18%—Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware10/12/202525/9/2026
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_store function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.40%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the formModifyPppAuthWhiteMac function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip, mac, v6 and remark parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel, and pModule parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.49%—Tenda G3 Firmware9/9/202517/6/2026
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStore function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.