Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
131 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | — | — | Arista WI FI Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the… | |
| Recibida | Alta (7.1) | — | — | Arista Wi-fi Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is… | |
| Recibida | Crítica (9) | — | — | Arista WI FI Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access… | |
| Recibida | Alta (7.7) | — | — | Arista WI FI Access PointAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode. | |
| Recibida | Crítica (9.4) | — | — | Arista Wi-fi Access PointsAI | 6/10/2026 | 6/10/2026 | On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition… | |
| Pendiente de análisis | Alta (8.7) | 0.36% | — | Buffalo WI FIAI | 28/9/2026 | 30/9/2026 | Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition. | |
| Pendiente de análisis | Alta (8.6) | 0.36% | — | Buffalo WI FIAI | 28/9/2026 | 30/9/2026 | BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command. | |
| Aplazada | Alta (8.9) | 3.6% | — | Shenzhen Aitemi M300 Wi-fi RepeaterAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may… | |
| Pendiente de análisis | Alta (7.5) | 0.15% | — | Lorex 2K Indoor Wi-fi Security CameraAI | 13/7/2026 | 14/7/2026 | Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. User interaction is not required to exploit this… | |
| Pendiente de análisis | Alta (7.5) | 0.41% | — | Lorex 2K Indoor Wi-fi Security CameraAI | 13/7/2026 | 14/7/2026 | Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. Authentication is not required to exploit this vulnerability. The… | |
| Aplazada | Crítica (9.3) | 2.9% | 💥 PoC | Shenzhen Aitemi M300 Wi-fi RepeaterAI | 1/7/2026 | 6/7/2026 | Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append… | |
| Aplazada | Media (5.2) | 0.13% | — | CP Plus Wi-fi CameraAI | 25/5/2026 | 23/7/2026 | This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing the UART interface and performing memory extraction to obtain sensitive information, including cryptographic private… | |
| Pendiente de análisis | Media (5.6) | 0.18% | 💥 PoC | NXP Moal.koAINXP Wi-fi DriverAI | 13/5/2026 | 17/6/2026 | NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overflow via the mod_para parameter in the woal_init_module_param function. | |
| Analizada | Alta (7.7) | 0.23% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel.… | |
| Analizada | Baja (2) | 0.36% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow… | |
| Aplazada | Alta (7.5) | 0.32% | — | Reolink Video Doorbell Wi-fiAI | 28/10/2025 | 17/6/2026 | Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing attackers to intercept or extract sensitive information. | |
| Analizada | Alta (8.8) | 0.15% | — | Realtek Wi-fi USB Driver | 2/9/2025 | 17/6/2026 | Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Realtek rtl81xx SDK Wi-Fi driver. An attacker must first obtain the ability to execute low-privileged code on the… | |
| Analizada | Alta (7.8) | 0.15% | — | Realtek Wi-fi USB Driver | 2/9/2025 | 17/6/2026 | Realtek RTL8811AU rtwlanu.sys N6CSet_DOT11_CIPHER_DEFAULT_KEY Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Realtek RTL8811AU drivers. An attacker must first obtain the ability to execute low-privileged… | |
| Analizada | Alta (8.8) | 0.15% | — | Realtek Wi-fi USB Driver | 2/9/2025 | 17/6/2026 | Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Realtek rtl81xx SDK Wi-Fi driver. An attacker must first obtain the ability to execute low-privileged code on the… | |
| Analizada | Baja (3.8) | 0.14% | — | Realtek Wi-fi USB Driver | 2/9/2025 | 17/6/2026 | Realtek RTL8811AU rtwlanu.sys N6CQueryInformationHandleCustomized11nOids Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of Realtek RTL8811AU drivers. An attacker must first obtain the ability to execute… | |
| Analizada | Alta (8.8) | 0.15% | — | Realtek Wi-fi USB Driver | 2/9/2025 | 30/9/2026 | Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Realtek rtl81xx SDK Wi-Fi driver. An attacker must first obtain the ability to execute… | |
| Analizada | Crítica (9.8) | 1.7% | — | Reolink Smart 2K+ Plug-in Wi-fi Video Doorbell With Chime Firmware | 22/8/2025 | 17/6/2026 | Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerability via the setddns_pip_system() function. | |
| Analizada | Alta (7.5) | 0.52% | — | Reolink Smart 2K+ Plug-in Wi-fi Video Doorbell With Chime Firmware | 22/8/2025 | 17/6/2026 | Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to cause a Denial of Service (DoS) via initiating a large number of simultaneous ffmpeg-based stream pushes. | |
| Aplazada | Media (4) | 0.14% | — | Reolink Smart 2K+ Plug-in Wi-fi Video DoorbellAI | 22/8/2025 | 17/6/2026 | Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system wide instead of an account-by-account basis, potentially leading to a Denial of Service (DoS) via resource exhaustion. NOTE: the Supplier reports that the system-wide limit is… | |
| Analizada | Alta (7.3) | 0.27% | — | Reolink Smart 2K+ Plug-in Wi-fi Video Doorbell With Chime Firmware | 22/8/2025 | 17/6/2026 | A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 when entering the wrong username and password allows attackers to enumerate existing accounts. |