Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.94% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 10/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the… | |
| Modificada | Alta (7.5) | 30% | 💥 Exploit | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key. | |
| Modificada | Alta (7.5) | 0.82% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to obtain a list of files in a specific directory, by using the regex feature in a package name. | |
| Modificada | Alta (7.5) | 20% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. | |
| Modificada | Alta (7.5) | 14% | — | Aigital Wireless-n Repeater Mini Router Firmware | 2/5/2023 | 17/6/2026 | An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user. | |
| Modificada | Media (5.4) | 29% | — | Aigital Wireless-n Repeater Mini Router Firmware | 28/4/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the wl_ssid parameter at /boafrm/formHomeWlanSetup. | |
| Modificada | Alta (7.3) | 7.6% | — | UI Edgemax Edgerouter Firmware | 28/4/2023 | 9/7/2026 | A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of the component Web Management Interface. Such manipulation of the argument ecn-up leads to command injection. The attack may be performed from remote. The exploit is publicly available and might be… | |
| Modificada | Crítica (9.8) | 2.2% | — | Aigital Wireless-n Repeater Mini Router Firmware | 26/4/2023 | 9/7/2026 | Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request. | |
| Modificada | Crítica (9.8) | 0.77% | — | Redline Router Firmware | 14/4/2023 | 17/6/2026 | Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17. | |
| Modificada | Crítica (9.8) | 0.77% | — | Redline Router Firmware | 14/4/2023 | 17/6/2026 | Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17. | |
| Modificada | Alta (7.5) | 0.99% | — | Xiaomi Router Firmware | 29/3/2023 | 17/6/2026 | When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command… | |
| Modificada | Alta (7.5) | 0.82% | — | Mikrotik Routeros | 27/3/2023 | 9/7/2026 | An issue in the bridge2 component of MikroTik RouterOS v6.40.5 allows attackers to cause a Denial of Service (DoS) via crafted packets. | |
| Modificada | Crítica (9.8) | 3.3% | — | UI Edgerouter X Firmware | 25/3/2023 | 17/6/2026 | A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical. Affected by this vulnerability is an unknown functionality of the component OSPF Handler. The manipulation of the argument area leads to command injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.8% | — | UI Edgerouter X Firmware | 25/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. Affected is an unknown function of the component Static Routing Configuration Handler. The manipulation of the argument next-hop-interface leads to command injection. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 1.8% | — | UI Edgerouter X Firmware | 25/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. This issue affects some unknown processing of the component NAT Configuration Handler. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.3) | 0.44% | — | Silabs Wireless Smart Ubiquitous Network Linux Border Router Firmware | 21/3/2023 | 17/6/2026 | Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network. | |
| Modificada | Alta (8.8) | 2.4% | — | Netmodule Router Software | 16/2/2023 | 17/6/2026 | The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploading malicious files to the web root directory, authenticated users could gain remote command execution with elevated privileges. This issue affects NSRW: from 4.3.0.0… | |
| Modificada | Alta (8.8) | 29% | 💥 PoC | Netmodule Router Software | 16/2/2023 | 17/6/2026 | NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119, from 4.4.0.0 before 4.4.0.118, from 4.6.0.0… | |
| Modificada | Alta (8.8) | 1.5% | — | Cisco Ic3000 Industrial Compute GatewayCisco IOXCisco IOS XECisco Cgr1240 Firmware+5 | 12/2/2023 | 17/6/2026 | A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An… | |
| Modificada | Alta (7.2) | 0.96% | — | Cisco Rv160 VPN Router FirmwareCisco Rv160w Wireless-ac VPN Router FirmwareCisco Rv260 VPN Router FirmwareCisco Rv260p VPN Router With POE Firmware | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user input. An… | |
| Modificada | Alta (8.6) | 0.56% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientID parameters. An unauthorized user could calculate this parameter and use it to… | |
| Modificada | Alta (8.1) | 0.49% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-284: Improper Access Control. They allow unauthenticated devices to subscribe to MQTT topics on the same network as the device manager. An unauthorized user who knows… | |
| Modificada | Crítica (9.1) | 0.32% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-760: Use of a One-way Hash with a Predictable Salt. They send MQTT credentials in response to HTTP/HTTPS requests from the cloud platform. These credentials are encoded… | |
| Modificada | Alta (7.2) | 1.6% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). An unauthorized user with privileged access to the local web interface… |