Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Adsl Road Runner Modem | 8/9/2005 | 16/6/2026 | ADSL Road Runner modem in the Annex A family has a service running on port 224, which allows remote attackers to login to the modem with a blank password and gain unauthorized access. | |
| Modificada | Alta (7.5) | 1.1% | — | Mentor Adslfr4ii | 16/8/2005 | 16/6/2026 | Mentor ADSL-FR4II router running firmware 2.00.0111 has an undocumented web server running on TCP port 5678, which allows local users to gain access. | |
| Modificada | Media (5) | 1.2% | — | Mentor Adslfr4ii | 16/8/2005 | 16/6/2026 | Mentor ADSL-FR4II router running firmware 2.00.0111 allows remote attackers to cause a denial of service (active TCP connections state table consumption) via a large number of connections, such as a port scan. | |
| Modificada | Baja (2.1) | 0.33% | — | Mentor Adslfr4ii | 16/8/2005 | 16/6/2026 | Mentor ADSL-FR4II router running firmware 2.00.0111 stores the web administration password in cleartext in the backup configuration file, which allows local users to obtain sensitive information. | |
| Modificada | Alta (7.2) | 0.34% | — | Mentor Adsl-fr4iiAI | 16/8/2005 | 16/6/2026 | The web administration interface in Mentor ADSL-FR4II router running firmware 2.00.0111 does not set a default password, which allows local users to gain access. | |
| Modificada | Alta (7.5) | 1.6% | — | Arcowave Systems Wlan AP + Adsl Router | 14/5/2005 | 16/6/2026 | Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell. | |
| Modificada | Media (5) | 1.5% | — | Securecomputing Samsung Adsl Modem | 2/5/2005 | 16/6/2026 | The Boa web server, as used in Samsung ADSL Modem SMDK8947v1.2 and possibly other products, allows remote attackers to read arbitrary files via a full pathname in the HTTP request. | |
| Modificada | Alta (7.5) | 1.7% | — | Securecomputing Samsung Adsl Modem | 2/5/2005 | 16/6/2026 | Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP request to adsl.cgi. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Edimax Full Rate Adsl Router | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Alta (7.5) | 1.7% | — | Edimax Full Rate Adsl Router | 31/12/2004 | 16/6/2026 | The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Conceptronic Cadslr1 Adsl Router | 31/12/2004 | 16/6/2026 | The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | BT Voyager 2000 Wireless Adsl Router | 6/12/2004 | 16/6/2026 | The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | 3com 3cradsl72 | 13/10/2004 | 16/6/2026 | The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to app_sta.stm. | |
| Modificada | Alta (10) | 3.6% | — | Zoom Model 5560 X3 Ethernet Adsl Modem | 6/8/2004 | 16/6/2026 | Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Ericsson Hm220dp Adsl Modem | 31/12/2003 | 16/6/2026 | The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side. | |
| Modificada | Alta (10) | 2.3% | — | Telindus 1120 Adsl Router | 31/12/2002 | 16/6/2026 | Telindus 1100 ASDL router running firmware 6.0.x uses weak encryption for UDP session traffic, which allows remote attackers to gain unauthorized access by sniffing and decrypting the administrative password. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Telindus Adsl Router | 4/10/2002 | 16/6/2026 | Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which generates a reply that includes the router's password and other sensitive information in cleartext. | |
| Modificada | Alta (7.5) | 2.4% | — | Alcatel Adsl Modem 1000Alcatel Speed Touch Adsl Modem | 31/12/2001 | 16/6/2026 | Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication. |