Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.20%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware26/10/202517/6/2026
Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.54%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware26/10/202517/6/2026
Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaBaja (2.1)0.17%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware25/10/202517/6/2026
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.37%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware25/10/202517/6/2026
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.37%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware25/10/202517/6/2026
Vulnerable Components in Azure Access OS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.30%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware25/10/202517/6/2026
Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaMedia (6.9)0.30%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware25/10/202517/6/2026
SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.22%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware25/10/202517/6/2026
Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.34%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware24/10/202517/6/2026
Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaMedia (5.2)0.11%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware23/10/202517/6/2026
Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.41%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware23/10/202517/6/2026
Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaMedia (5.3)0.21%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware21/10/202517/6/2026
HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.19%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware20/10/202517/6/2026
Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.26%—Azure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware17/10/202517/6/2026
Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
AnalizadaCrítica (10)0.37%💥 PoCAzure-access Blu-ic2 FirmwareAzure-access Blu-ic4 Firmware15/10/202517/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Flooding.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
ModificadaMedia (4.6)0.15%—Idec Kit-fc6a-24-kc FirmwareIdec Kit-fc6a-24-pc FirmwareIdec Kit-fc6a-24-ra FirmwareIdec Kit-fc6a-24-ra-hg1g Firmware+874/9/202417/6/2026
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated.
ModificadaMedia (6.8)0.40%—Gncchome Gncc C2 Firmware15/8/202417/6/2026
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.
ModificadaMedia (4.6)0.26%—Gncchome Gncc C2 Firmware15/8/202417/6/2026
Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.
AnalizadaMedia (6.8)0.36%—Gncchome Gncc C2 Firmware15/8/202417/6/2026
Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices
ModificadaCrítica (9.8)1.2%—Commscope Arris Surfboard Sbg6950ac2 Firmware26/1/202417/6/2026
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.
ModificadaAlta (7.5)1.2%—Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Control 1515sp PC2 FirmwareSiemens Simatic S7-1500 CPU 1510sp F-1 PN Firmware+6912/12/202317/6/2026
Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A restart is needed to restore normal operations.
ModificadaAlta (7.1)0.67%—Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+6714/11/202317/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0),…
ModificadaCrítica (9.4)1.3%—Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+6714/11/202317/6/2026
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323.
ModificadaMedia (5.9)0.88%—Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+6714/11/202317/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0),…
ModificadaMedia (5.1)1.0%—Siemens 6gk5205-3bb00-2ab2 FirmwareSiemens 6gk5205-3bb00-2tb2 FirmwareSiemens 6gk5205-3bd00-2tb2 FirmwareSiemens 6gk5205-3bd00-2ab2 Firmware+6714/11/202317/6/2026
Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device needs to be restarted for the web interface to become available again.