Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

275 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.9)0.33%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an empty list does not enforce any restrictions and allows all network traffic to pass unfiltered.
AnalizadaMedia (4.9)0.33%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these values are not supported and do not trigger any validation error. Instead, they are silently interpreted as network 0 which results in no networks being blocked at all.
AnalizadaAlta (8.8)0.56%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwriting arbitrary files on the device and achieving a full system compromise.
AnalizadaAlta (8.8)0.56%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the contents of the backup archive to create or overwrite arbitrary files anywhere on the system.
AnalizadaAlta (8.1)0.34%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the system.
AnalizadaMedia (6.5)0.52%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system. The endpoint accepts a parameter specifying the log file to open (e.g., /tmp/weblog{some_number}), but this parameter is not properly validated, allowing an attacker to modify it to reference any…
AnalizadaMedia (6.5)0.35%—Mbs-solutions Universal Bacnet Router Firmware9/3/202617/6/2026
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to read arbitrary files on the system.
AplazadaMedia (6.9)0.42%—Asus Router FirmwareAI25/11/202517/6/2026
A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory…
AplazadaAlta (8.2)0.65%—Asus Router FirmwareAIWebdavAI25/11/202517/6/2026
A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
AnalizadaMedia (5.3)0.42%—Cisco IOS XECisco Cgr1000 FirmwareCisco Ir510 Wpan FirmwareCisco Ic3000 Industrial Compute Gateway Firmware+37/5/202517/6/2026
A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the…
AnalizadaAlta (7.2)2.1%—Bectechnologies Router Firmware23/4/202517/6/2026
BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers. Although authentication is required to exploit this vulnerability, the existing…
AnalizadaMedia (6.5)0.45%—Bectechnologies Router Firmware23/4/202517/6/2026
BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The…
AnalizadaMedia (5.3)0.91%—Bectechnologies Router Firmware23/4/202517/6/2026
BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface.…
AnalizadaMedia (6.5)0.49%—Bectechnologies Router Firmware23/4/202517/6/2026
BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is required to exploit this vulnerability. The specific flaw exists…
ModificadaAlta (7.2)7.5%—Mc-technologies MC LR Router Firmware21/11/202417/6/2026
Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability…
ModificadaAlta (7.2)6.0%—Mc-technologies MC LR Router Firmware21/11/202417/6/2026
Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability…
ModificadaAlta (7.2)7.5%—Mc-technologies MC LR Router Firmware21/11/202417/6/2026
Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability…
AnalizadaAlta (7.2)10%—Mc-technologies MC LR Router Firmware21/11/202417/6/2026
An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
AnalizadaAlta (7.2)0.62%—Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware2/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. In order to exploit this vulnerability, the attacker must have valid admin…
AnalizadaAlta (8.8)0.59%—Cisco Rv340 Dual WAN Gigabit VPN Router FirmwareCisco Rv340w Dual WAN Gigabit Wireless-ac VPN Router FirmwareCisco Rv345 Dual WAN Gigabit VPN Router FirmwareCisco Rv345p Dual WAN Gigabit POE VPN Router Firmware2/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability exists because the web-based management interface discloses sensitive…
AnalizadaMedia (5.3)0.15%—Google Nest Wifi PRO FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi Router Firmware16/9/202417/6/2026
U-Boot environment is read from unauthenticated partition.
AnalizadaAlta (8.8)0.58%—Cisco IOS XRCisco Network Services OrchestratorCisco Small Business RV Series Router Firmware11/9/202417/6/2026
This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications…
AnalizadaAlta (7.1)0.38%—Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+413/8/202417/6/2026
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
AnalizadaAlta (7.1)0.34%—Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+413/8/202417/6/2026
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
AnalizadaMedia (6.1)0.33%—Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+413/8/202417/6/2026
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.