Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.36% | — | Asus RouterAI | 4/12/2024 | 17/6/2026 | An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2024 ASUS Router Improper Input Validation' section on the ASUS Security Advisory for more information. | |
| Aplazada | Alta (7.2) | 1.1% | — | Billion Electric RouterAI | 29/11/2024 | 17/6/2026 | Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device. | |
| Aplazada | Alta (7.2) | 0.63% | — | Billion Electric RouterAI | 29/11/2024 | 17/6/2026 | Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords. | |
| Aplazada | Alta (7.5) | 0.54% | — | Billion Electric RouterAI | 29/11/2024 | 17/6/2026 | Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages. | |
| Aplazada | Alta (8.6) | 0.46% | — | Billion Electric RouterAI | 29/11/2024 | 17/6/2026 | Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device. | |
| Analizada | Alta (7.3) | 0.76% | — | Qnap Qurouter | 22/11/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later | |
| Analizada | Crítica (9.5) | 1.5% | — | Qnap Qurouter | 22/11/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3.103 and later | |
| Modificada | Alta (7.2) | 7.5% | — | Mc-technologies MC LR Router Firmware | 21/11/2024 | 17/6/2026 | Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability… | |
| Modificada | Alta (7.2) | 6.0% | — | Mc-technologies MC LR Router Firmware | 21/11/2024 | 17/6/2026 | Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability… | |
| Modificada | Alta (7.2) | 7.5% | — | Mc-technologies MC LR Router Firmware | 21/11/2024 | 17/6/2026 | Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability… | |
| Analizada | Alta (7.2) | 10% | — | Mc-technologies MC LR Router Firmware | 21/11/2024 | 17/6/2026 | An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Aplazada | Crítica (9.1) | 0.56% | — | Kasda Linksmart Router Kw5515AI | 20/11/2024 | 17/6/2026 | An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters. | |
| Aplazada | Crítica (9.1) | 1.0% | — | Kasda Linksmart Router Kw6512AI | 20/11/2024 | 17/6/2026 | Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters. | |
| Aplazada | Baja (2.4) | 0.27% | 💥 PoC | Hathway Skyworth Router Cm5100-511AI | 15/11/2024 | 5/7/2026 | Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext. | |
| Aplazada | Baja (3.5) | 0.21% | — | Tp-link Mesh Wi-fi Router Rp562bAI | 12/11/2024 | 17/6/2026 | Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain information of the other devices connected through the Wi-Fi. | |
| Aplazada | Media (4.6) | 0.20% | — | Mesh Wi-fi Router Rp562bAI | 12/11/2024 | 17/6/2026 | Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain or alter the settings of the device . | |
| Aplazada | Media (6.5) | 0.26% | — | Shenzhen Tuoshi Network Communications 5G CPE Router Nr500-eaAI | 24/10/2024 | 17/6/2026 | Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication. | |
| Aplazada | Alta (8.8) | 1.7% | — | Wuhan Tianyu Information Industry CO LTD Tianyu CPE RouterAI | 24/10/2024 | 17/6/2026 | Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp. | |
| Aplazada | Alta (8.8) | 1.7% | — | Shenzhen Tuoshi Network Communications 5G CPE Router Nr500-eaAI | 24/10/2024 | 17/6/2026 | Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp. | |
| Analizada | Media (6.9) | 0.61% | — | Ccontrols Basrouter Bacnet Basrt-b Firmware | 10/10/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This affects an unknown part of the component UDP Packet Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Alta (7.2) | 0.62% | — | Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware | 2/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. In order to exploit this vulnerability, the attacker must have valid admin… | |
| Analizada | Alta (8.8) | 0.59% | — | Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware | 2/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability exists because the web-based management interface discloses sensitive… | |
| Aplazada | Alta (8) | 1.3% | — | Gigastone TR1 Travel Router R101AI | 25/9/2024 | 17/6/2026 | Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the ssid parameter in the request. | |
| Aplazada | Alta (8.1) | 0.56% | — | ZTE RouterAI | 16/9/2024 | 17/6/2026 | The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory /var/lua_session, the function iterates on all files in this directory and executes them using the function dofile without any validation if it is a valid… | |
| Aplazada | Crítica (9.8) | 0.48% | — | ZTE RouterAI | 16/9/2024 | 17/6/2026 | The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of data in post request. The checksum is sent encrypted in the request, the function decrypts it and stores the checksum on the stack… |