Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.1%—Beeline Smart BOX Firmware10/11/202117/6/2026
Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.
ModificadaAlta (8.8)0.71%—Beeline Smart BOX Firmware10/11/202117/6/2026
Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.
ModificadaCrítica (10)0.96%—Skyworth Penguin Aurora BOX Firmware26/10/202117/6/2026
Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital. An unauthorized access vulnerability exists in the Penguin Aurora Box. An attacker can use the vulnerability to gain unauthorized access to a specific link to remotely control the TV.
ModificadaAlta (7.2)1.9%—Telmat Accesslog FirmwareTelmat Educ@box FirmwareTelmat Git@box Firmware24/9/202017/6/2026
The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated code injection over the network.
ModificadaCrítica (9.8)2.0%—Telmat Accesslog FirmwareTelmat Educ@box FirmwareTelmat Git@box Firmware24/9/202017/6/2026
The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the network.
ModificadaAlta (8.8)4.9%—Beeline Smart BOX Firmware29/4/202017/6/2026
Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslookup nslookup_ipaddr parameter, or the Traceroute traceroute_ipaddr parameter.
ModificadaAlta (7.8)0.33%—Bitdefender BOX Firmware31/10/201917/6/2026
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API. In order to exploit this vulnerability, an attacker needs presence in Bitdefender BOX setup network and Bitdefender BOX be in setup mode.
ModificadaMedia (4.4)0.32%—Bitdefender BOX Firmware17/10/201917/6/2026
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to…
ModificadaAlta (8.8)3.1%💥 ExploitSMA Sunny Webbox Firmware9/10/201913/7/2026
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease…
ModificadaCrítica (9.8)2.1%—Kddi Smart TV BOX Firmware12/9/201917/6/2026
Smart TV Box firmware version prior to 1300 allows remote attackers to bypass access restriction to conduct arbitrary operations on the device without user's intent, such as installing arbitrary software or changing the device settings via Android Debug Bridge port 5555/TCP.
ModificadaCrítica (9.8)2.9%—Blackbox Icompel FirmwareOnelan Net-top-box Firmware26/8/201917/6/2026
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
ModificadaAlta (8.8)9.4%—Indionetworks Unibox Firmware21/3/201917/6/2026
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system commands on the server with root user privileges. Authentication for accessing this…
ModificadaAlta (8.8)9.4%—Indionetworks Unibox Firmware21/3/201917/6/2026
An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system commands on the server with root user privileges. Authentication for accessing…
ModificadaAlta (8.8)4.9%—Indionetworks Unibox Firmware21/3/201917/6/2026
An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute code on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard…
ModificadaAlta (7.5)1.2%—MXQ Project MXQ TV BOX Firmware28/12/201817/6/2026
The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that contains an exported broadcast receiver application component that, when called, will…
ModificadaAlta (7.1)0.28%—MXQ Project MXQ TV BOX Firmware28/12/201817/6/2026
The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that dynamically registers a broadcast receiver app component named…
ModificadaAlta (7.5)0.92%—Orange Airbox Firmware16/10/201817/6/2026
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials.
ModificadaAlta (7.5)1.5%—Orange Airbox Firmware16/10/201817/6/2026
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.
ModificadaCrítica (9.8)1.3%—Orange Airbox Firmware16/10/201817/6/2026
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.
ModificadaAlta (7.5)1.5%—Zipato Zipabox Firmware13/8/201817/6/2026
Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface.
ModificadaCrítica (9.8)1.1%—Zipato Zipabox Firmware13/8/201817/6/2026
Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extract clear text passwords and get root access on the device.
ModificadaCrítica (9.8)2.4%—Zipato Zipabox Firmware13/8/201817/6/2026
Insecure configuration storage in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows remote attacker perform new attack vectors and take under control device and smart home.
ModificadaAlta (7.5)1.0%—Arcadyan Swisscom Internet-box Firmware29/6/201717/6/2026
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure.
ModificadaAlta (7.5)4.6%💥 ExploitSagemcom Livebox Firmware9/3/201717/6/2026
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled within minutes. An attacker can exploit this issue to render the affected system unresponsive, resulting in a denial-of-service condition for telephone, Internet, and TV…
ModificadaMedia (6.1)1.5%—Fortinet Fortisandbox Firmware26/5/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet FortiSandbox before 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) serial parameter to alerts/summary/profile/; the (2) urlForCreatingReport parameter to csearch/report/export/; the (3) id…
Orbitaley — Vulnerabilidades