Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

34 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.75%—Linksys Wrt54g Firmware4/9/202417/6/2026
A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter Handler. The manipulation of the argument services_array leads to stack-based buffer overflow. The attack may be…
AnalizadaAlta (8.8)0.32%—Linksys Wrt54g Firmware19/7/202417/6/2026
Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.
ModificadaMedia (4.3)0.48%—Linksys Wrt54gl Firmware10/2/202417/6/2026
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects unknown code of the file /SysInfo1.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (4.3)0.36%—Linksys Wrt54gl Firmware10/2/202417/6/2026
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown part of the file /wlaninfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. The identifier…
ModificadaAlta (7.5)0.77%—Linksys Wrt54gl Firmware9/2/202417/6/2026
A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unknown functionality of the file /SysInfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used.…
ModificadaAlta (7.2)9.1%—Linksys Wrt54gl Firmware22/5/20239/7/2026
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining…
ModificadaAlta (7.2)1.9%💥 PoCLinksys Wrt54gl Firmware9/1/202317/6/2026
An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this…
ModificadaAlta (7.5)1.3%—Linksys Wrt54gl Firmware9/1/202317/6/2026
A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.
ModificadaAlta (7.2)19%—Linksys Wrt54gl Firmware9/1/202317/6/2026
A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated attacker with administrator privileges to execute arbitrary commands on the underlying Linux…
ModificadaAlta (7.5)1.3%—Cisco Linksys Wrt54gx Router FirmwareLinksys Wrt54gx22/11/201116/6/2026
The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests.
ModificadaAlta (7.5)1.3%—Cisco Linksys Wrt54g Router FirmwareLinksys Wrt54gCisco Linksys Wrt54gs Router FirmwareLinksys Wrt54gs22/11/201116/6/2026
The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP…
ModificadaAlta (7.8)2.2%—Cisco Linksys Wrt54gc RouterCisco Linksys Wrt54gc Router Firmware24/1/201116/6/2026
Buffer overflow in the web-based management interface on the Cisco Linksys WRT54GC router with firmware before 1.06.1 allows remote attackers to cause a denial of service (device crash) via a long string in a POST request.
ModificadaAlta (10)4.6%—Linksys Wrt54gl24/9/200916/6/2026
Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco…
ModificadaMedia (6.8)3.4%💥 ExploitCisco Wrt54gc6/5/200916/6/2026
Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that change the administrator password via the sysPasswd and sysConfirmPasswd parameters.
ModificadaAlta (7.5)3.1%—Linksys Wrt54g10/3/200816/6/2026
The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a file that lists all HTML documents, and an ELF executable file.
ModificadaAlta (7.8)1.6%—Linksys Wrt54g10/3/200816/6/2026
The Linksys WRT54G router allows remote attackers to cause a denial of service (device restart) via a long username and password to the FTP interface.
ModificadaAlta (10)5.2%💥 ExploitLinksys Wrt54g10/3/200816/6/2026
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers to perform arbitrary administrative actions via a direct request to (1) Advanced.tri, (2) AdvRoute.tri, (3) Basic.tri, (4) ctlog.tri, (5) ddns.tri, (6) dmz.tri, (7)…
ModificadaAlta (10)2.5%—Linksys Wrt54g10/3/200816/6/2026
The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to establish an FTP session by sending an arbitrary username and password.
ModificadaMedia (4)1.0%—Linksys Wrt54g10/3/200816/6/2026
The Linksys WRT54G router stores passwords and keys in cleartext in the Config.bin file, which might allow remote authenticated users to obtain sensitive information via an HTTP request for the top-level Config.bin URI.
ModificadaAlta (9.3)3.3%💥 PoCLinksys Wrt54gl10/1/200816/6/2026
Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.
ModificadaMedia (5)1.3%—Linksys Wag200gLinksys Wrt54gc21/3/200716/6/2026
The Linksys WAG200G with firmware 1.01.01, WRT54GC 2 with firmware 1.00.7, and WRT54GC 1 with firmware 1.03.0 and earlier allow remote attackers to obtain sensitive information (passwords and configuration data) via a packet to UDP port 916. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)4.1%💥 ExploitLinksys Wrt54g10/10/200616/6/2026
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
ModificadaAlta (7.5)1.7%—Linksys Wrt54gLinksys Wrt54g V524/5/200616/6/2026
Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
ModificadaMedia (5)1.8%—Linksys Wrt54g V57/3/200616/6/2026
Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single…
ModificadaAlta (7.8)1.4%—Linksys Befw11s4Linksys Befw11s4 V3Linksys Befw11s4 V4Linksys Wrt54gs15/12/200516/6/2026
Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND). NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.
Orbitaley — Vulnerabilidades