Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.58% | — | Sound4 Stream ExtensionSound4 WM2 FirmwareSound4 BIG Voice2 FirmwareSound4 BIG Voice4 Firmware+5 | 30/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack active user sessions and gain unauthorized access to the application. | |
| Modificada | Crítica (9.3) | 1.6% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 30/12/2025 | 24/9/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code… | |
| Analizada | Alta (8.6) | 0.24% | — | Sound4 Playout Ula8 FirmwareSound4 Stream X8 FirmwareSound4 Stream X4 FirmwareSound4 Stream X2 Firmware+11 | 22/12/2025 | 17/6/2026 | SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem… | |
| Modificada | Alta (8.8) | 0.98% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 22/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining… | |
| Analizada | Crítica (9.3) | 3.4% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 22/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to… | |
| Modificada | Alta (8.8) | 1.2% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Stream Extension+5 | 22/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data POST requests with directory traversal… | |
| Modificada | Media (5.1) | 0.19% | — | Sound4 Impact FirmwareSound4 Pulse FirmwareSound4 First FirmwareSound4 Impact ECO Firmware+5 | 22/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when… | |
| Modificada | Crítica (9.3) | 0.74% | — | Sound4 First FirmwareSound4 Impact ECO FirmwareSound4 Pulse ECO FirmwareSound4 BIG Voice4 Firmware+5 | 22/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized… | |
| Analizada | Crítica (9.3) | 0.85% | — | Sound4 Stream ExtensionSound4 WM2 FirmwareSound4 BIG Voice2 FirmwareSound4 BIG Voice4 Firmware+5 | 22/12/2025 | 17/6/2026 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication. | |
| Analizada | Alta (7.5) | 0.19% | — | Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware | 10/12/2025 | 25/9/2026 | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and upload unencrypted sensitive information. Note that this occurs without disclosure or consent from the manufacturer. | |
| Analizada | Media (6.5) | 0.28% | — | Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware | 10/12/2025 | 25/9/2026 | NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs. | |
| Analizada | Alta (8.1) | 0.23% | — | Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware | 10/12/2025 | 25/9/2026 | Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails to validate firmware signatures during updates, uses outdated cryptographic… | |
| Analizada | Crítica (9.8) | 0.98% | — | Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware | 10/12/2025 | 25/9/2026 | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution. | |
| Analizada | Alta (7.3) | 0.80% | — | Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware | 10/12/2025 | 25/9/2026 | Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 allows attackers to execute arbitrary commands with root privileges through malicious domain names. | |
| Analizada | Alta (7.4) | 0.18% | — | Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware | 10/12/2025 | 25/9/2026 | Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections for discovery services and CoAP gateway communications, enabling man-in-the-middle attacks on device control and monitoring. | |
| Analizada | Alta (7.4) | 0.18% | — | Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware | 10/12/2025 | 25/9/2026 | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept firmware update traffic and potentially serve modified firmware files. | |
| Analizada | Baja (2.1) | 0.77% | — | Yottamaster DM2 FirmwareYottamaster DM3 FirmwareYottamaster Dm200 Firmware | 8/12/2025 | 1/10/2026 | A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File Upload. Performing manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The… | |
| Modificada | Alta (8.7) | 0.67% | — | Tp-link Fr307-m2 FirmwareTp-link Fr205 FirmwareTp-link Fr365 FirmwareTp-link G611 Firmware+9 | 21/10/2025 | 17/6/2026 | An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. | |
| Modificada | Crítica (9.3) | 3.3% | — | Tp-link Er8411 FirmwareTp-link Er7412-m2 FirmwareTp-link Er707-m2 FirmwareTp-link Er7206 Firmware+9 | 21/10/2025 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. | |
| Analizada | Crítica (9.3) | 1.0% | — | Tp-link Er8411 FirmwareTp-link Er7412-m2 FirmwareTp-link Er707-m2 FirmwareTp-link Er7206 Firmware+9 | 21/10/2025 | 17/6/2026 | An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. | |
| Analizada | Alta (8.6) | 0.69% | — | Tp-link Er706w FirmwareTp-link Er706w-4g FirmwareTp-link Er7212pc FirmwareTp-link G36 Firmware+9 | 21/10/2025 | 17/6/2026 | An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. | |
| Modificada | Media (5.5) | 1.9% | — | Fujitsu Esprimo D556/2 FirmwareFujitsu Esprimo D6011 FirmwareFujitsu Esprimo D6012 FirmwareFujitsu Esprimo D7010 Firmware+183 | 7/12/2023 | 17/6/2026 | A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a specific address during the DXE phase of… | |
| Modificada | Media (4.3) | 0.23% | — | MRL Mr-gm3-d FirmwareMRL Mr-gm3-k FirmwareMRL Mr-gm3-s FirmwareMRL Mr-gm3-dks Firmware+3 | 11/10/2023 | 17/6/2026 | Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-W) firmware Ver. 1.03.45 and earlier allows a network-adjacent unauthenticated attacker to intercept wireless LAN communication, when the affected product performs the communication without changing… | |
| Modificada | Media (4.7) | 0.11% | — | Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware | 11/8/2023 | 17/6/2026 | Race condition in firmware for some Intel(R) Ethernet Controllers and Adapters E810 Series before version 1.7.2.4 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.5) | 0.32% | — | Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+1 | 3/7/2023 | 17/6/2026 | All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext… |