Vulnerabilidades em Tenda

807 resultados
Análise Vexday

O portfólio de vulnerabilidades da Tenda acumula 757 CVEs catalogadas, volume expressivo que, aliado às 116 entradas surgidas nos últimos 90 dias, indica ritmo elevado de descobertas recentes e superfície de ataque em expansão. Embora nenhuma vulnerabilidade conste no catálogo KEV da CISA — taxa abaixo da média geral do catálogo —, a existência de 130 CVEs com prova de conceito pública representa risco operacional concreto, pois reduz significativamente a barreira para exploração oportunista. O tipo de falha mais frequente é CWE-121 (stack-based buffer overflow), classe que historicamente viabiliza execução remota de código em dispositivos de rede embarcados. A CVE mais perigosa em destaque atualmente é CVE-2024-10697, com score EPSS de 0,2551, indicando probabilidade não trivial de exploração e merecedora de atenção prioritária em planos de remediação.

CVE-2025-15252HIGHTenda M3 setDhcpAP formSetRemoteDhcpForAp stack-based overflowEPSS 3.3%CVE-2026-3399HIGHTenda F453 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflowEPSS 3.2%CVE-2026-3168HIGHTenda F453 httpd NatStaticSetting fromNatStaticSetting buffer overflowEPSS 3.2%CVE-2025-12236HIGHTenda CH22 DhcpListClient fromDhcpListClient buffer overflowEPSS 3.2%CVE-2026-6989MEDIUMTenda F453 Telnet Service telnet TendaTelnet command injectionEPSS 3.2%CVE-2026-2911HIGHTenda FH451 GstDhcpSetSer buffer overflowEPSS 3.1%CVE-2025-7795HIGHTenda FH451 P2pListFilter fromP2pListFilter stack-based overflowEPSS 3.1%CVE-2026-7102MEDIUMTenda F456 httpd WriteFacMac FromWriteFacMac command injectionEPSS 3.0%CVE-2026-8264MEDIUMTenda AC6 httpd WifiApScan formWifiApScan os command injectionEPSS 2.9%CVE-2025-15234HIGHTenda M3 setInternetLanInfo formSetRemoteInternetLanInfo heap-based overflowEPSS 2.8%CVE-2026-1687MEDIUMTenda HG10 Boa Webserver formSamba command injectionEPSS 2.8%CVE-2026-2910HIGHTenda HG9 formPing6 stack-based overflowEPSS 2.7%CVE-2025-5836MEDIUMTenda AC9 POST Request SetIPTVCfg formSetIptv command injectionEPSS 2.7%CVE-2026-1689MEDIUMTenda HG10 Login formLogin checkUserFromLanOrWan command injectionEPSS 2.7%CVE-2026-4906HIGHTenda AC5 POST Request WizardHandle decodePwd stack-based overflowEPSS 2.6%CVE-2026-3808HIGHTenda FH1202 webtypelibrary formWebTypeLibrary stack-based overflowEPSS 2.6%CVE-2026-5204HIGHTenda CH22 Parameter webtypelibrary formWebTypeLibrary stack-based overflowEPSS 2.5%CVE-2026-86148CRITICALTenda CP3 Kylin system.c SystemAsh os command injectionEPSS 2.5%CVE-2026-19747CRITICALTenda CH7 ATE Module Kylin HandleCmd command injectionEPSS 2.4%CVE-2026-1638MEDIUMTenda AC21 mDMZSetCfg command injectionEPSS 2.1%