Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 3.8% | — | Alcatel Speedtouch 7G RouterBT Home HUB | 12/10/2007 | 16/6/2026 | The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the end of the PATH_INFO to cgi/b, aka "double-slash auth bypass." NOTE: remote… | |
| Modificada | Media (4.3) | 0.61% | — | Alcatel Speedtouch 7G RouterBT Home HUB | 12/10/2007 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to perform actions as administrators via unspecified POST requests, as demonstrated by enabling an inbound remote-assistance HTTPS session on… | |
| Modificada | Media (4.3) | 1.1% | — | Alcatel Speedtouch 7G RouterBT Home HUB | 12/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Alcatel-lucent Omnipcx | 7/6/2007 | 16/6/2026 | Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems. | |
| Modificada | Alta (10) | 3.1% | — | Alcatel-lucent Voice Mail System | 2/4/2007 | 16/6/2026 | Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID). | |
| Modificada | Alta (7.5) | 2.3% | — | Alcatel-lucent Omniaccess WirelessAruba Mobility Controller | 14/2/2007 | 16/6/2026 | The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN. | |
| Modificada | Alta (7.5) | 6.1% | — | Alcatel-lucent Omniaccess WirelessAruba Mobility Controller | 14/2/2007 | 16/6/2026 | Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings. | |
| Modificada | Media (5) | 1.8% | — | Alcatel OmniswitchAlcatel Omniswitch 7800 | 31/12/2004 | 16/6/2026 | Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled. | |
| Modificada | Media (5) | 5.0% | — | Alcatel-lucent Omnipcx | 31/12/2003 | 16/6/2026 | The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite. | |
| Modificada | Alta (10) | 3.6% | — | Alcatel-lucent Omnipcx | 31/12/2002 | 16/6/2026 | Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (10) | 5.3% | — | Alcatel AOS | 11/12/2002 | 16/6/2026 | Alcatel OmniSwitch 7700/7800 switches running AOS 5.1.1 contains a back door telnet server that was intended for development but not removed before distribution, which allows remote attackers to gain administrative privileges. | |
| Modificada | Baja (2.1) | 0.29% | — | Alcatel-lucent Omnipcx | 31/5/2002 | 16/6/2026 | Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system. | |
| Modificada | Media (6.2) | 0.29% | — | Alcatel-lucent Omnipcx | 31/5/2002 | 16/6/2026 | FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file. | |
| Modificada | Media (4.6) | 0.31% | — | Alcatel-lucent Omnipcx | 31/5/2002 | 16/6/2026 | Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges. | |
| Modificada | Media (5) | 1.9% | — | Alcatel Speed Touch Home | 25/3/2002 | 16/6/2026 | Alcatel Speed Touch Home ADSL Modem allows remote attackers to cause a denial of service (reboot) via a network scan with unusual packets, such as nmap with OS detection. | |
| Modificada | Alta (7.5) | 2.4% | — | Alcatel Adsl Modem 1000Alcatel Speed Touch Adsl Modem | 31/12/2001 | 16/6/2026 | Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication. | |
| Modificada | Alta (7.5) | 2.0% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations. | |
| Modificada | Alta (7.5) | 3.7% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login. | |
| Modificada | Alta (7.5) | 3.5% | — | Alcatel Speed Touch Home | 10/4/2001 | 16/6/2026 | Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access. | |
| Modificada | Media (5) | 1.7% | — | Alcatel Omniswitch | 31/3/1999 | 16/6/2026 | Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time. |