Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

309 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.41%—Edimax Br-6476ac Firmware27/1/20255/7/2026
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.
AplazadaAlta (8.3)0.85%—Iocharger AC FirmwareAI9/1/202517/6/2026
After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers. This issue affects Iocharger firmware for AC models before firmware version 25010801. The issue is addressed by requiring a…
AnalizadaMedia (5.1)29%—Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware25/11/202417/6/2026
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_iperf. The manipulation of the argument iperf leads to command injection. The attack may be launched remotely. The…
AnalizadaMedia (5.1)29%—Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware25/11/202417/6/2026
A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/network/ajax_getChannelList. The manipulation of the argument countryCode leads to command injection. The attack can be…
AnalizadaMedia (5.1)29%—Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware25/11/202417/6/2026
A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown function of the file /admin/network/diag_nslookup. The manipulation of the argument diag_nslookup leads to command injection. It is possible to launch the attack remotely.…
AnalizadaMedia (5.1)29%—Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware25/11/202417/6/2026
A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing of the file /admin/network/diag_ping6. The manipulation of the argument diag_ping6 leads to command injection. The attack may be initiated…
AnalizadaMedia (5.1)29%—Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware25/11/202417/6/2026
A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. The manipulation of the argument diag_ping leads to command injection. The attack can be initiated remotely. The…
AnalizadaMedia (5.1)29%—Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware25/11/202417/6/2026
A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file /admin/network/diag_traceroute6. The manipulation of the argument diag_traceroute6 leads to command injection. It is possible to initiate the attack remotely.…
AnalizadaMedia (5.1)29%—Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware25/11/202417/6/2026
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_traceroute. The manipulation of the argument diag_traceroute leads to command injection. The attack may be…
AnalizadaMedia (5.1)30%—Engeniustech Enh1350ext FirmwareEngeniustech Ens500-ac FirmwareEngeniustech Ens620ext Firmware25/11/202417/6/2026
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sn_package/sn_https. The manipulation of the argument https_enable leads to command injection. The attack can be…
AnalizadaMedia (5.1)27%—Engeniustech Enh1350ext FirmwareEngeniustech Ens620ext FirmwareEngeniustech Ens500-ac Firmware25/11/202417/6/2026
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown function of the file /admin/network/wifi_schedule. The manipulation of the argument wifi_schedule_day_em_5 leads to command injection. It is possible to launch the attack…
ModificadaMedia (4.6)0.15%—Idec Kit-fc6a-24-kc FirmwareIdec Kit-fc6a-24-pc FirmwareIdec Kit-fc6a-24-ra FirmwareIdec Kit-fc6a-24-ra-hg1g Firmware+874/9/202417/6/2026
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated.
AnalizadaMedia (6.1)0.68%—Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+1012/8/202417/6/2026
An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior enables an unauthenticated remote attacker to bypass authentication via a specially crafted direct request when another user has an active session.
AnalizadaAlta (8.7)1.7%—Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+1012/8/202417/6/2026
A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to read arbitrary files and bypass authentication.
AnalizadaCrítica (9.4)0.77%—Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+1012/8/202417/6/2026
Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a denial of service. A specially-crafted HTTP request to pre-authentication resources…
AnalizadaCrítica (10)1.1%—Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+1012/8/202417/6/2026
Stack-based buffer overflow vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to execute arbitrary code.
AnalizadaCrítica (9.4)1.3%—Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+1012/8/202417/6/2026
Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an authenticated remote attacker to execute arbitrary OS commands via various endpoint parameters.
AnalizadaAlta (8.8)0.80%—Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+1012/8/202417/6/2026
Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication and factory reset the device via unprotected goform endpoints.
AnalizadaAlta (8.7)0.63%—Vonets Var1200-h FirmwareVonets Var1200-l FirmwareVonets Var600-h FirmwareVonets Vap11ac Firmware+108/8/202417/6/2026
Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication using hard-coded administrator credentials. These accounts cannot be disabled.
ModificadaAlta (7.8)0.16%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1021/7/202417/6/2026
Memory corruption while handling user packets during VBO bind operation.
ModificadaAlta (7.8)0.15%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2181/7/202417/6/2026
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
ModificadaAlta (7.8)0.13%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1071/7/202417/6/2026
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
ModificadaAlta (7.8)0.10%—Qualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+3391/7/202417/6/2026
Memory corruption when allocating and accessing an entry in an SMEM partition.
ModificadaAlta (7.8)0.10%—Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2201/7/202417/6/2026
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
ModificadaAlta (7.8)0.10%—Qualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+2551/7/202417/6/2026
Memory corruption while processing key blob passed by the user.