Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.98% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality. | |
| Modificada | Crítica (9.8) | 2.1% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in. | |
| Modificada | Alta (8.8) | 0.87% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization and access the hidden resources in the… | |
| Modificada | Alta (8.8) | 0.74% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclosing credentials of administrative accounts in plain-text. | |
| Modificada | Crítica (9.8) | 0.95% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system. | |
| Modificada | Alta (8.8) | 0.43% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious web page and execute CRUD commands (GET, POST, PUT, DELETE) to perform arbitrary operations in the system. | |
| Modificada | Crítica (9.1) | 1.2% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GET parameter, unauthenticated attackers can remotely delete arbitrary files on the affected device and cause denial of service scenario. | |
| Modificada | Alta (7.5) | 20% | 💥 Exploit | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information. | |
| Modificada | Crítica (9.1) | 1.2% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC. | |
| Modificada | Alta (7.5) | 83% | 💥 Exploit | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device. | |
| Modificada | Crítica (9.8) | 2.3% | — | Ecoa ECS Router Controller-ecs FirmwareEcoa Riskbuster FirmwareEcoa Riskterminator | 30/9/2021 | 17/6/2026 | ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to execute arbitrary code on the affected device. | |
| Modificada | Crítica (9.1) | 1.8% | — | Cisco IOS XECisco IOS XE Sd-wanCisco IOS XE Sd-wan 16.10.1 When Installed ON 1000 Series Integrated ServicesCisco IOS XE Sd-wan 16.10.1 When Installed ON 4000 Series Integrated Services+142 | 23/9/2021 | 17/6/2026 | A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory… | |
| Modificada | Alta (8.8) | 1.5% | — | Netmodule Router Software | 23/8/2021 | 17/6/2026 | Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800. | |
| Modificada | Crítica (9.8) | 1.5% | — | Netmodule Router Software | 23/8/2021 | 17/6/2026 | Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800. | |
| Modificada | Alta (7.5) | 1.1% | — | Netmodule Router Software | 23/8/2021 | 17/6/2026 | Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800. | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | Cisco Application Extension PlatformCisco Rv110w Wireless-n VPN Firewall FirmwareCisco Rv130 VPN Router FirmwareCisco Rv130w Wireless-n Multifunction VPN Router Firmware+1 | 18/8/2021 | 17/6/2026 | A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This… | |
| Modificada | Alta (8.8) | 9.1% | — | Cisco Small Business RV Series Router Firmware | 4/8/2021 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) condition Execute arbitrary commands For more information about… | |
| Modificada | Crítica (9.8) | 9.7% | — | Cisco Small Business RV Series Router Firmware | 4/8/2021 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) condition Execute arbitrary commands For more information about… | |
| Modificada | Crítica (9.8) | 2.0% | — | Cisco Small Business RV Series Router Firmware | 4/8/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient user input… | |
| Modificada | Media (6.5) | 2.1% | — | Mikrotik Routeros | 21/7/2021 | 17/6/2026 | Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet. | |
| Modificada | Media (6.5) | 2.9% | — | Mikrotik Routeros | 21/7/2021 | 17/6/2026 | Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU. | |
| Modificada | Media (6.5) | 2.0% | — | Mikrotik Routeros | 21/7/2021 | 17/6/2026 | Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). | |
| Modificada | Media (6.5) | 1.8% | — | Mikrotik Routeros | 19/7/2021 | 17/6/2026 | Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenticated remote attacker can cause a Denial of Service. | |
| Modificada | Media (6.5) | 1.8% | — | Mikrotik Routeros | 19/7/2021 | 17/6/2026 | Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU. | |
| Modificada | Media (6.5) | 1.9% | — | Mikrotik Routeros | 19/7/2021 | 17/6/2026 | Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU. |