Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

26.291 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)1.4%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the…
AnalizadaAlta (8.8)0.44%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.
AnalizadaAlta (8.5)0.88%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the…
AnalizadaAlta (8.6)0.88%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the…
AnalizadaAlta (8.6)0.88%—Waterfall-security Wf-500 Firmware29/5/202621/7/2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the…
AnalizadaCrítica (10)0.31%—Acer Wave 7 Firmware29/5/202621/7/2026
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.
AnalizadaCrítica (10)0.61%—Acer Wave 7 Firmware29/5/202621/7/2026
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
AnalizadaCrítica (10)2.2%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
AnalizadaAlta (8.3)0.34%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.
AnalizadaCrítica (10)0.53%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.
AnalizadaAlta (8.6)0.66%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands.
AnalizadaAlta (8.7)0.37%—Acer Predator Connect W6X Firmware29/5/202621/7/2026
Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.
AnalizadaAlta (7.3)0.13%—Tp-link Tapo L535e FirmwareTp-link Tapo P300 FirmwareTp-link Tapo D100c Firmware28/5/202617/6/2026
TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker within the Bluetooth range could exploit this…
AnalizadaAlta (8.7)0.40%💥 PoCTp-link Archer C64 Firmware28/5/202617/6/2026
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. Successful exploitation could allow an…
AnalizadaCrítica (9.8)1.8%—Inhandnetworks Ir315 FirmwareInhandnetworks Ir302 FirmwareInhandnetworks Ir615 FirmwareInhandnetworks Ir305 Firmware28/5/202617/6/2026
A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
AnalizadaCrítica (9.8)1.8%—Inhandnetworks Ir315 FirmwareInhandnetworks Ir302 FirmwareInhandnetworks Ir615 FirmwareInhandnetworks Ir305 Firmware28/5/202617/6/2026
A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
AnalizadaCrítica (9.8)1.8%—Inhandnetworks Ir315 FirmwareInhandnetworks Ir302 FirmwareInhandnetworks Ir615 FirmwareInhandnetworks Ir305 Firmware28/5/202617/6/2026
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
AnalizadaCrítica (9.8)1.8%—Inhandnetworks Ir315 FirmwareInhandnetworks Ir302 FirmwareInhandnetworks Ir615 FirmwareInhandnetworks Ir305 Firmware28/5/202617/6/2026
A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
ModificadaAlta (8.5)5.2%—Tp-link Archer Be450 FirmwareTp-link Archer Be7200 Firmware27/5/202617/6/2026
An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can leverage the browser’s developer console…
AnalizadaAlta (8.7)0.57%—Tp-link Re305 FirmwareTp-link Re360 FirmwareTp-link Re580d FirmwareTp-link Re650 Firmware+122/5/202623/7/2026
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of…
AnalizadaAlta (7.5)0.40%—ZTE Mu5250 Firmware22/5/202623/7/2026
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.
AnalizadaAlta (7.7)0.59%—UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2722/5/202623/7/2026
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information.
AnalizadaCrítica (10)46%⚠ Explotación activa💥 ExploitUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2722/5/202623/7/2026
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
AnalizadaCrítica (10)1.8%⚠ Explotación activaUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2822/5/202623/7/2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
AnalizadaCrítica (10)15%⚠ Explotación activa💥 ExploitUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2722/5/202623/7/2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.