Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)3.8%—Alcatel Speedtouch 7G RouterBT Home HUB12/10/200716/6/2026
The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the end of the PATH_INFO to cgi/b, aka "double-slash auth bypass." NOTE: remote…
ModificadaMedia (4.3)0.61%—Alcatel Speedtouch 7G RouterBT Home HUB12/10/200716/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to perform actions as administrators via unspecified POST requests, as demonstrated by enabling an inbound remote-assistance HTTPS session on…
ModificadaMedia (4.3)1.1%—Alcatel Speedtouch 7G RouterBT Home HUB12/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.2%—Alcatel-lucent Omnipcx7/6/200716/6/2026
Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems.
ModificadaAlta (10)3.1%—Alcatel-lucent Voice Mail System2/4/200716/6/2026
Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).
ModificadaAlta (7.5)2.3%—Alcatel-lucent Omniaccess WirelessAruba Mobility Controller14/2/200716/6/2026
The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN.
ModificadaAlta (7.5)6.1%—Alcatel-lucent Omniaccess WirelessAruba Mobility Controller14/2/200716/6/2026
Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings.
ModificadaMedia (5)1.8%—Alcatel OmniswitchAlcatel Omniswitch 780031/12/200416/6/2026
Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled.
ModificadaMedia (5)5.0%—Alcatel-lucent Omnipcx31/12/200316/6/2026
The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
ModificadaAlta (10)3.6%—Alcatel-lucent Omnipcx31/12/200216/6/2026
Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access.
ModificadaAlta (10)5.3%—Alcatel AOS11/12/200216/6/2026
Alcatel OmniSwitch 7700/7800 switches running AOS 5.1.1 contains a back door telnet server that was intended for development but not removed before distribution, which allows remote attackers to gain administrative privileges.
ModificadaBaja (2.1)0.29%—Alcatel-lucent Omnipcx31/5/200216/6/2026
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.
ModificadaMedia (6.2)0.29%—Alcatel-lucent Omnipcx31/5/200216/6/2026
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.
ModificadaMedia (4.6)0.31%—Alcatel-lucent Omnipcx31/5/200216/6/2026
Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.
ModificadaMedia (5)1.9%—Alcatel Speed Touch Home25/3/200216/6/2026
Alcatel Speed Touch Home ADSL Modem allows remote attackers to cause a denial of service (reboot) via a network scan with unusual packets, such as nmap with OS detection.
ModificadaAlta (7.5)2.4%—Alcatel Adsl Modem 1000Alcatel Speed Touch Adsl Modem31/12/200116/6/2026
Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication.
ModificadaAlta (7.5)2.0%—Alcatel Speed Touch Home10/4/200116/6/2026
Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations.
ModificadaAlta (7.5)3.7%—Alcatel Speed Touch Home10/4/200116/6/2026
The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.
ModificadaAlta (7.5)3.5%—Alcatel Speed Touch Home10/4/200116/6/2026
Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access.
ModificadaMedia (5)1.7%—Alcatel Omniswitch31/3/199916/6/2026
Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time.
Orbitaley — Vulnerabilidades