Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.20% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 26/10/2025 | 17/6/2026 | Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.54% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 26/10/2025 | 17/6/2026 | Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Baja (2.1) | 0.17% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 25/10/2025 | 17/6/2026 | Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.37% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 25/10/2025 | 17/6/2026 | Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.37% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 25/10/2025 | 17/6/2026 | Vulnerable Components in Azure Access OS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.30% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 25/10/2025 | 17/6/2026 | Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Media (6.9) | 0.30% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 25/10/2025 | 17/6/2026 | SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.22% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 25/10/2025 | 17/6/2026 | Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.34% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 24/10/2025 | 17/6/2026 | Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Media (5.2) | 0.11% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 23/10/2025 | 17/6/2026 | Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.41% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 23/10/2025 | 17/6/2026 | Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Media (5.3) | 0.21% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 21/10/2025 | 17/6/2026 | HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.19% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 20/10/2025 | 17/6/2026 | Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.26% | — | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 17/10/2025 | 17/6/2026 | Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Analizada | Crítica (10) | 0.37% | 💥 PoC | Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware | 15/10/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Flooding.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | |
| Modificada | Media (4.6) | 0.15% | — | Idec Kit-fc6a-24-kc FirmwareIdec Kit-fc6a-24-pc FirmwareIdec Kit-fc6a-24-ra FirmwareIdec Kit-fc6a-24-ra-hg1g Firmware+87 | 4/9/2024 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated. | |
| Modificada | Media (6.8) | 0.40% | — | Gncchome Gncc C2 Firmware | 15/8/2024 | 17/6/2026 | Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port. | |
| Modificada | Media (4.6) | 0.26% | — | Gncchome Gncc C2 Firmware | 15/8/2024 | 17/6/2026 | Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port. | |
| Analizada | Media (6.8) | 0.36% | — | Gncchome Gncc C2 Firmware | 15/8/2024 | 17/6/2026 | Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices | |
| Modificada | Crítica (9.8) | 1.2% | — | Commscope Arris Surfboard Sbg6950ac2 Firmware | 26/1/2024 | 17/6/2026 | An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root. | |
| Modificada | Alta (7.5) | 1.2% | — | Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Control 1515sp PC2 FirmwareSiemens Simatic S7-1500 CPU 1510sp F-1 PN Firmware+69 | 12/12/2023 | 17/6/2026 | Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A restart is needed to restore normal operations. | |
| Modificada | Alta (7.1) | 0.67% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0),… | |
| Modificada | Crítica (9.4) | 1.3% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323. | |
| Modificada | Media (5.9) | 0.88% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0),… | |
| Modificada | Media (5.1) | 1.0% | — | Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+67 | 14/11/2023 | 17/6/2026 | Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device needs to be restarted for the web interface to become available again. |