Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.48%—ZTE RouterAI16/9/202417/6/2026
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the stack without checking its length. An…
AplazadaAlta (8.1)0.38%—ZTE RouterAI16/9/202417/6/2026
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to decrypt RSA encrypted ciphertext, the decrypted data is stored on the stack without checking its length. An authenticated attacker can get RCE as root by…
AnalizadaMedia (5.3)0.15%—Google Nest Wifi PRO FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi Router Firmware16/9/202417/6/2026
U-Boot environment is read from unauthenticated partition.
AnalizadaAlta (8.8)0.58%—Cisco IOS XRCisco Network Services OrchestratorCisco Small Business RV Series Router Firmware11/9/202417/6/2026
This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications…
AplazadaAlta (8)0.54%—Shenzhen Haichangxing Technology HCX H822 4G LTE RouterAI10/9/20245/7/2026
Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.
AplazadaMedia (5.7)0.60%—Buffalo Wireless LAN RouterAIBuffalo Wireless LAN RepeaterAI10/9/202417/6/2026
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
AplazadaAlta (8)0.30%—Teldat Router Rs123AITeldat Router Rs123wAI27/8/202417/6/2026
A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges
AnalizadaAlta (7.5)0.86%—Apollographql Apollo-routerApollographql Apollo Helms-charts RouterApollographql Apollo Router27/8/202417/6/2026
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if _all_ of the following are true: 1. The Apollo…
AnalizadaAlta (7.5)0.99%—Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+127/8/202417/6/2026
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.…
AnalizadaAlta (7.1)0.38%—Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+413/8/202417/6/2026
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
AnalizadaAlta (7.1)0.34%—Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+413/8/202417/6/2026
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
AnalizadaMedia (6.1)0.33%—Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+413/8/202417/6/2026
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
AnalizadaAlta (7.1)0.49%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M826-2 Shdsl-router Firmware+2213/8/202417/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1…
AnalizadaAlta (7.3)0.44%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M826-2 Shdsl-router Firmware+2213/8/202417/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1…
AnalizadaAlta (8.6)0.77%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M826-2 Shdsl-router Firmware+2213/8/202417/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1…
AplazadaMedia (6.8)0.85%—Elecom Wireless LAN RouterAI1/8/202417/6/2026
OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execute an arbitrary OS command.
AplazadaMedia (6.8)0.36%—Elecom Wireless LAN RouterAI1/8/202417/6/2026
Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution.
AplazadaAlta (8.8)0.50%💥 PoCNepstech Wifi Router XponAI17/7/202417/6/2026
Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without the user's consent, leading to a potential account takeover.
AnalizadaAlta (7.5)0.27%—Synology Router Manager28/6/202417/6/2026
Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.
AnalizadaMedia (5.9)0.52%—Synology Router Manager28/6/202417/6/2026
Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors.
AplazadaCrítica (10)1.1%—Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance RouterAI27/6/202417/6/2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redundant peer allows a network based attacker to bypass authentication and take full control of the device. Only routers or conductors that are running in high-availability…
AplazadaMedia (6.5)0.27%—Openthread Border RouterAISilabs Multi Protocol GatewayAI27/6/202417/6/2026
In a Silicon Labs multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service.
AplazadaAlta (8.4)0.48%—Nepstech Wifi Router XponAINepstech Ntpl-xpon1gfevnAI25/6/202417/6/2026
An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary code via the router's Telnet port 2345 without requiring authentication credentials.
AplazadaCrítica (9.3)0.36%—Baicells Snap Router Baice BMIAI25/6/202417/6/2026
Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the device.
AplazadaAlta (8.8)6.3%—Dlink Wireless RoutersAI17/6/202417/6/2026
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
Orbitaley — Vulnerabilidades