Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.1% | — | Beeline Smart BOX Firmware | 10/11/2021 | 17/6/2026 | Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi. | |
| Modificada | Alta (8.8) | 0.71% | — | Beeline Smart BOX Firmware | 10/11/2021 | 17/6/2026 | Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm. | |
| Modificada | Crítica (10) | 0.96% | — | Skyworth Penguin Aurora BOX Firmware | 26/10/2021 | 17/6/2026 | Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital. An unauthorized access vulnerability exists in the Penguin Aurora Box. An attacker can use the vulnerability to gain unauthorized access to a specific link to remotely control the TV. | |
| Modificada | Alta (7.2) | 1.9% | — | Telmat Accesslog FirmwareTelmat Educ@box FirmwareTelmat Git@box Firmware | 24/9/2020 | 17/6/2026 | The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated code injection over the network. | |
| Modificada | Crítica (9.8) | 2.0% | — | Telmat Accesslog FirmwareTelmat Educ@box FirmwareTelmat Git@box Firmware | 24/9/2020 | 17/6/2026 | The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the network. | |
| Modificada | Alta (8.8) | 4.9% | — | Beeline Smart BOX Firmware | 29/4/2020 | 17/6/2026 | Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslookup nslookup_ipaddr parameter, or the Traceroute traceroute_ipaddr parameter. | |
| Modificada | Alta (7.8) | 0.33% | — | Bitdefender BOX Firmware | 31/10/2019 | 17/6/2026 | An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API. In order to exploit this vulnerability, an attacker needs presence in Bitdefender BOX setup network and Bitdefender BOX be in setup mode. | |
| Modificada | Media (4.4) | 0.32% | — | Bitdefender BOX Firmware | 17/10/2019 | 17/6/2026 | An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to… | |
| Modificada | Alta (8.8) | 3.1% | 💥 Exploit | SMA Sunny Webbox Firmware | 9/10/2019 | 13/7/2026 | An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease… | |
| Modificada | Crítica (9.8) | 2.1% | — | Kddi Smart TV BOX Firmware | 12/9/2019 | 17/6/2026 | Smart TV Box firmware version prior to 1300 allows remote attackers to bypass access restriction to conduct arbitrary operations on the device without user's intent, such as installing arbitrary software or changing the device settings via Android Debug Bridge port 5555/TCP. | |
| Modificada | Crítica (9.8) | 2.9% | — | Blackbox Icompel FirmwareOnelan Net-top-box Firmware | 26/8/2019 | 17/6/2026 | Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP. | |
| Modificada | Alta (8.8) | 9.4% | — | Indionetworks Unibox Firmware | 21/3/2019 | 17/6/2026 | An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system commands on the server with root user privileges. Authentication for accessing this… | |
| Modificada | Alta (8.8) | 9.4% | — | Indionetworks Unibox Firmware | 21/3/2019 | 17/6/2026 | An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system commands on the server with root user privileges. Authentication for accessing… | |
| Modificada | Alta (8.8) | 4.9% | — | Indionetworks Unibox Firmware | 21/3/2019 | 17/6/2026 | An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute code on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard… | |
| Modificada | Alta (7.5) | 1.2% | — | MXQ Project MXQ TV BOX Firmware | 28/12/2018 | 17/6/2026 | The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that contains an exported broadcast receiver application component that, when called, will… | |
| Modificada | Alta (7.1) | 0.28% | — | MXQ Project MXQ TV BOX Firmware | 28/12/2018 | 17/6/2026 | The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, versionName=4.4.2-20170213) that dynamically registers a broadcast receiver app component named… | |
| Modificada | Alta (7.5) | 0.92% | — | Orange Airbox Firmware | 16/10/2018 | 17/6/2026 | goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login using the default admin:admin credentials. | |
| Modificada | Alta (7.5) | 1.5% | — | Orange Airbox Firmware | 16/10/2018 | 17/6/2026 | goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter. | |
| Modificada | Crítica (9.8) | 1.3% | — | Orange Airbox Firmware | 16/10/2018 | 17/6/2026 | goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Zipato Zipabox Firmware | 13/8/2018 | 17/6/2026 | Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface. | |
| Modificada | Crítica (9.8) | 1.1% | — | Zipato Zipabox Firmware | 13/8/2018 | 17/6/2026 | Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extract clear text passwords and get root access on the device. | |
| Modificada | Crítica (9.8) | 2.4% | — | Zipato Zipabox Firmware | 13/8/2018 | 17/6/2026 | Insecure configuration storage in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows remote attacker perform new attack vectors and take under control device and smart home. | |
| Modificada | Alta (7.5) | 1.0% | — | Arcadyan Swisscom Internet-box Firmware | 29/6/2017 | 17/6/2026 | Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Sagemcom Livebox Firmware | 9/3/2017 | 17/6/2026 | Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled within minutes. An attacker can exploit this issue to render the affected system unresponsive, resulting in a denial-of-service condition for telephone, Internet, and TV… | |
| Modificada | Media (6.1) | 1.5% | — | Fortinet Fortisandbox Firmware | 26/5/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet FortiSandbox before 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) serial parameter to alerts/summary/profile/; the (2) urlForCreatingReport parameter to csearch/report/export/; the (3) id… |