Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

94 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.88%—Sophos AP6 Series Wireless Access PointAI9/9/202517/6/2026
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7).
AplazadaCrítica (9.8)1.1%—HPE Networking Instant ON Access PointsAI8/7/202517/6/2026
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.
AplazadaAlta (7.2)1.5%—HPE Networking Instant ON Access PointsAI8/7/202517/6/2026
An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user.
AplazadaAlta (7.2)1.4%—Hikvision Wireless Access PointAI13/6/202517/6/2026
Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
AplazadaCrítica (9.8)1.4%—Aruba Access PointAI25/9/202417/6/2026
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute…
AplazadaMedia (5.3)0.21%—UI Unifi U6 Access PointAI22/7/202417/6/2026
A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point. Affected Products: UniFi U6+ Access Point (Version 6.6.65 and earlier) Mitigation: Update your UniFi U6+ Access Point to Version 6.6.74 or later.
AplazadaMedia (4.8)0.20%—UI Unifi IOS APPAIUI Unifi Access PointAI9/7/202417/6/2026
UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not using UniFi Network Application) that could cause the SSID name to change and/or the WiFi Password to be removed on the 5GHz Radio. This vulnerability is fixed in UniFi iOS app 10.15.2 and later.
AplazadaAlta (8.4)0.49%—Arista Wireless Access PointsAI27/6/202417/6/2026
This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require high permissions to exploit this vulnerability,…
AplazadaMedia (4.3)0.20%—Octolize Woocommerce UPS Shipping Live Rates AND Access PointsAI10/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Octolize WooCommerce UPS Shipping – Live Rates and Access Points.This issue affects WooCommerce UPS Shipping – Live Rates and Access Points: from n/a through 2.2.4.
AnalizadaAlta (8.6)0.63%—Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software27/3/202417/6/2026
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this…
AplazadaMedia (5.9)0.25%—Cisco Access Point SoftwareAI27/3/202417/6/2026
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected device. This vulnerability exists because unnecessary commands are available…
AplazadaAlta (7.5)0.52%—UI Unifi Access PointsAIUI Unifi SwitchesAIUI Unifi LTE BackupAIUI Unifi ExpressAI20/2/202417/6/2026
A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi…
ModificadaAlta (8.8)0.34%—Cisco Business 140ac Access Point FirmwareCisco Business 141acm FirmwareCisco Business 142acm FirmwareCisco Business 143acm Firmware+418/5/202317/6/2026
A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login implementation. An attacker could exploit…
ModificadaMedia (6.7)0.24%—Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE23/3/202317/6/2026
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator…
ModificadaMedia (5.5)0.26%—Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE23/3/202317/6/2026
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this…
ModificadaAlta (7.5)1.4%—Cisco Aironet Access Point Software15/4/202217/6/2026
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device may experience a performance degradation in…
ModificadaMedia (5.5)0.26%—ABB System Access Point 2.0 FirmwareABB System Access Point 127v FirmwareABB Wl-system Access Point 127v FirmwareABB Wl-system Access Point Firmware+123/9/202117/6/2026
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.
ModificadaAlta (7.4)0.36%—Cisco Aironet Access Point Software23/9/202117/6/2026
A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect error handling when an…
ModificadaMedia (4.4)0.23%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software24/3/202117/6/2026
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability…
ModificadaMedia (6.7)0.27%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software24/3/202117/6/2026
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that manages system startup processes. An attacker could exploit this vulnerability…
ModificadaAlta (7.4)0.39%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 Firmware24/3/202117/6/2026
A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of incoming mDNS traffic. An…
ModificadaAlta (7.5)1.5%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software24/3/202117/6/2026
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker…
ModificadaCrítica (9.8)4.4%—Zyxel ZLDZyxel Access Points Firmware27/11/202017/6/2026
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
ModificadaAlta (7.5)1.0%—UI Unifi Meshing Access Point FirmwareUI Unifi Controller Firmware27/10/202017/6/2026
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provide unintended network access.
ModificadaAlta (7.5)9.6%—Qualcomm Mobile Access Point15/10/202017/6/2026
The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the process, causing denial of service. This…