Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.41% | — | Netgear Rax30 Firmware | 16/12/2022 | 17/6/2026 | The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device. | |
| Modificada | Alta (8.8) | 0.49% | — | Netgear Rax30 Firmware | 16/12/2022 | 17/6/2026 | A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means. | |
| Modificada | Alta (8.8) | 1.2% | — | Netgear Nighthawk Ax1800 FirmwareNetgear Nighthawk Ax2400 FirmwareNetgear Nighthawk Ax3000 FirmwareNetgear Nighthawk Ax5400 Firmware+2 | 16/12/2022 | 17/6/2026 | The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication. | |
| Modificada | Crítica (10) | 0.91% | — | Netgear Ax2400 Firmware | 9/12/2022 | 17/6/2026 | A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are firewall restrictions in place that define access restrictions for IPv4 traffic, these restrictions do not appear to be… | |
| Modificada | Crítica (9.8) | 1.0% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec. | |
| Modificada | Crítica (9.8) | 1.0% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec. | |
| Modificada | Crítica (9.8) | 1.0% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip. | |
| Modificada | Crítica (9.8) | 1.0% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1. | |
| Modificada | Crítica (9.8) | 1.4% | — | Netgear R7000p Firmware | 22/11/2022 | 9/7/2026 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear R7000p Firmware | 22/11/2022 | 17/6/2026 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri. | |
| Modificada | Alta (8.8) | 1.9% | — | Netgear R6220 Firmware | 17/10/2022 | 17/6/2026 | Netgear R6220 v1.1.0.114_1.0.1 suffers from Incorrect Access Control, resulting in a command injection vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Netgear R7000 Firmware | 23/9/2022 | 17/6/2026 | Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat | |
| Modificada | Crítica (9.8) | 1.2% | — | Netgear Wnr2000v4 Firmware | 23/9/2022 | 17/6/2026 | Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcpy. | |
| Modificada | Crítica (9.8) | 1.2% | — | Netgear Wnr2000v4 Firmware | 22/9/2022 | 17/6/2026 | Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd. | |
| Modificada | Alta (7.8) | 0.54% | — | Netgear R7000 Firmware | 22/9/2022 | 17/6/2026 | Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy. | |
| Modificada | Media (5.3) | 0.29% | — | Netgear Wpn824ext Firmware | 20/9/2022 | 17/6/2026 | An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to replace the user-uploaded firmware image with an original old firmware image. This affects Firmware 1.1.1_1.1.9 and earlier. | |
| Modificada | Alta (7.5) | 0.35% | — | Netgear Wpn824ext Firmware | 20/9/2022 | 17/6/2026 | An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the CRC check. A successful attack can either introduce a backdoor to the device or make the device DoS. This… | |
| Modificada | Alta (8.8) | 25% | — | Netgear R6200 | 8/9/2022 | 9/7/2026 | Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter. |