Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.5% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' and 'SubnetMask' parameters are directly concatenated into shell commands executed via system(). An… | |
| Modificada | Media (5.4) | 1.5% | — | Dlink Dir-823g Firmware | 13/11/2025 | 5/7/2026 | A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /tmp/new_qos.rule configuration file. The vulnerability occurs because parsed fields from the configuration file are concatenated into command… | |
| Modificada | Media (6.8) | 0.56% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets reads up to 127 bytes, causing a stack… | |
| Modificada | Media (6.5) | 3.5% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in prog.cgi is stored in NVRAM and later used by librcm.so to construct iptables commands executed via… | |
| Modificada | Media (6.5) | 3.6% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construct system commands… | |
| Analizada | Media (6.5) | 3.2% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_433188` function in `prog.cgi` stores user-supplied email configuration parameters (`EmailFrom`, `EmailTo`, `SMTPServerAddress`, `SMTPServerPort`, `AccountName`) in NVRAM… | |
| Analizada | Media (6.5) | 3.2% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These values are later… | |
| Analizada | Alta (7.3) | 3.9% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_432F60` function in `prog.cgi` stores user-supplied `SetSysLogSettings/IPAddress` values in NVRAM via `nvram_safe_set("SysLogRemote_IPAddress", ...)`. These values are… | |
| Analizada | Alta (7.3) | 3.8% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_4438A4` function in `prog.cgi` stores user-supplied DDNS parameters (`ServerAddress` and `Hostname`) in NVRAM via `nvram_safe_set`. These values are later retrieved in the… | |
| Modificada | Media (5.4) | 1.4% | — | Dlink Dir-823g Firmware | 13/11/2025 | 5/7/2026 | A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /var/system/linux_vlan_reinit file. The vulnerability occurs because content read from this file is only partially validated for a prefix and then… | |
| Analizada | Crítica (9.3) | 4.0% | — | Dlink Dir-1260 Firmware | 6/11/2025 | 17/6/2026 | D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management interface that allows for unauthenticated attackers to execute arbitrary commands on the device with root privileges. The flaw specifically exists within the… | |
| Analizada | Media (4.4) | 0.10% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this vulnerability leading to Denial of service. | |
| Analizada | Media (6.7) | 0.14% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain confidential information. | |
| Analizada | Media (6.7) | 0.37% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell CloudLink. | |
| Analizada | Alta (7.2) | 0.33% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system. | |
| Analizada | Alta (8.4) | 0.65% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell access of system. | |
| Analizada | Crítica (9.1) | 0.38% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is… | |
| Analizada | Alta (7.2) | 1.0% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system. | |
| Analizada | Crítica (9.3) | 9.8% | — | Dlink Dns-343 Firmware | 29/10/2025 | 17/6/2026 | D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test functionality. The web maintenance script posts to the internal goForm endpoint '/goform/Mail_Test' and uses several form parameters directly in a call to a system email… | |
| Analizada | Baja (2.1) | 4.0% | — | Dlink Di-7001mini-8g Firmware | 27/10/2025 | 17/6/2026 | A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is an unknown function of the file /msp_info.htm. Such manipulation of the argument cmd leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2) | 7.0% | — | Dlink Dap-2695 Firmware | 27/10/2025 | 17/6/2026 | A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Update Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This… | |
| Analizada | Media (6.6) | 0.45% | — | Dlink Dap-2695 Firmware | 27/10/2025 | 17/6/2026 | A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler. Executing manipulation can lead to improper verification of cryptographic signature. The attack can be launched remotely. Attacks of this nature are highly complex. The… | |
| Analizada | Alta (7.5) | 0.42% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter. | |
| Analizada | Alta (7.5) | 0.37% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule. | |
| Analizada | Alta (7.5) | 0.37% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog. |