Vulnerabilidades em Tenda

807 resultados
Análise Vexday

O portfólio de vulnerabilidades da Tenda acumula 757 CVEs catalogadas, volume expressivo que, aliado às 116 entradas surgidas nos últimos 90 dias, indica ritmo elevado de descobertas recentes e superfície de ataque em expansão. Embora nenhuma vulnerabilidade conste no catálogo KEV da CISA — taxa abaixo da média geral do catálogo —, a existência de 130 CVEs com prova de conceito pública representa risco operacional concreto, pois reduz significativamente a barreira para exploração oportunista. O tipo de falha mais frequente é CWE-121 (stack-based buffer overflow), classe que historicamente viabiliza execução remota de código em dispositivos de rede embarcados. A CVE mais perigosa em destaque atualmente é CVE-2024-10697, com score EPSS de 0,2551, indicando probabilidade não trivial de exploração e merecedora de atenção prioritária em planos de remediação.

CVE-2026-9428HIGHTenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflowEPSS 0.8%CVE-2026-6631HIGHTenda F451 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflowEPSS 0.8%CVE-2025-15177HIGHTenda WH450 HTTP Request SetIpBind stack-based overflowEPSS 0.8%CVE-2025-15178HIGHTenda WH450 HTTP Request VirtualSer stack-based overflowEPSS 0.8%CVE-2025-15163HIGHTenda WH450 SafeEmailFilter stack-based overflowEPSS 0.8%CVE-2025-15162HIGHTenda WH450 RouteStatic stack-based overflowEPSS 0.8%CVE-2025-15164HIGHTenda WH450 SafeMacFilter stack-based overflowEPSS 0.8%CVE-2026-5849MEDIUMTenda i12 HTTP path traversalEPSS 0.8%CVE-2026-5962MEDIUMTenda CH22 httpd R7WebsSecurityHandlerfunction path traversalEPSS 0.8%CVE-2026-6024MEDIUMTenda i6 HTTP R7WebsSecurityHandlerfunction path traversalEPSS 0.8%CVE-2026-5841MEDIUMTenda i3 HTTP R7WebsSecurityHandler path traversalEPSS 0.8%CVE-2026-7036MEDIUMTenda i9 HTTP R7WebsSecurityHandlerfunction path traversalEPSS 0.8%CVE-2025-14993HIGHTenda AC18 HTTP Request SetDlnaCfg sprintf stack-based overflowEPSS 0.8%CVE-2025-12211HIGHTenda O3 setDmzInfo GetValue stack-based overflowEPSS 0.8%CVE-2025-4867HIGHTenda A15 ArpNerworkSet formArpNerworkSet denial of serviceEPSS 0.8%CVE-2025-8958HIGHTenda TX3 fast_setting_wifi_set stack-based overflowEPSS 0.8%CVE-2026-11405CRITICALHidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interfaceEPSS 0.8%CVE-2026-2138HIGHTenda TX9 SetStaticRouteCfg sub_42D03C buffer overflowEPSS 0.8%CVE-2026-2137HIGHTenda TX3 SetIpMacBind buffer overflowEPSS 0.8%CVE-2026-2140HIGHTenda TX9 setMacFilterCfg sub_4223E0 buffer overflowEPSS 0.8%