Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
133 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 2.8% | — | Ruijie M18-ew FirmwareRuijie Rg-ew1200r Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | |
| Analizada | Alta (8.8) | 1.7% | — | Ruijie Rg-yst250f FirmwareRuijie Rg-est310 V2 FirmwareRuijie Reyee OSRuijie Rg-eap602 Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-YST AP_3.0(1)B11P280YST250F allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common.lua. | |
| Analizada | Alta (8.8) | 2.6% | — | Ruijie X30 PRO FirmwareRuijie Rg-ew300 PRO Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | |
| Analizada | Alta (8.8) | 2.6% | — | Ruijie Rg-ew1800gx PRO FirmwareRuijie Rg-ew300n Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua. | |
| Analizada | Alta (8.8) | 2.0% | — | Ruijie Rg-bcr600w Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the restart_modules in file /usr/lib/lua/luci/controller/admin/common.lua. | |
| Analizada | Alta (8.8) | 2.8% | — | Ruijie Rg-ew1200g PRO FirmwareRuijie Rg-eap602 Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. | |
| Analizada | Alta (8.8) | 3.3% | — | Ruijie X30 PRO FirmwareRuijie Rg-ew300 PRO Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/host_access_delay.lua. | |
| Analizada | Alta (8.8) | 3.2% | — | Ruijie X30 PRO FirmwareRuijie Rg-ew300 PRO FirmwareRuijie Rg-eap602 Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless.lua. | |
| Analizada | Alta (8.8) | 2.8% | — | Ruijie Rg-ew300t FirmwareRuijie X30 PRO Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie X30 PRO V1 X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | |
| Analizada | Alta (8.8) | 2.9% | — | Ruijie Rg-ew1800gx FirmwareRuijie Rg-ew300r Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua. | |
| Analizada | Alta (8.8) | 2.9% | — | Ruijie Rg-ew1200g PRO FirmwareRuijie Rg-ew1200r Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua. | |
| Analizada | Alta (8.8) | 2.8% | — | Ruijie M18-ew FirmwareRuijie Rg-ew300g PRO Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. | |
| Analizada | Alta (8.8) | 3.5% | — | Ruijie Rg-bcr860 Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_service in file /usr/lib/lua/luci/controller/admin/service.lua. | |
| Analizada | Alta (8.8) | 2.4% | — | Ruijie Rg-bcr600w Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run_tcpdump in file /usr/lib/lua/luci/controller/admin/common_tcpdump.lua. | |
| Analizada | Alta (8.8) | 2.9% | — | Ruijie Rg-ew1200 FirmwareRuijie Rg-x60 Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | |
| Analizada | Alta (8.8) | 2.9% | — | Ruijie Rg-ew1200 FirmwareRuijie Rg-ew300 PRO Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua. | |
| Analizada | Alta (8.8) | 2.1% | — | Ruijie Rg-yst250f FirmwareRuijie Rg-est310 V2 FirmwareRuijie Reyee OSRuijie Rg-eap602 Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. | |
| Analizada | Alta (8.8) | 2.0% | — | Ruijie Rg-yst250f FirmwareRuijie Rg-est310 V2 FirmwareRuijie Reyee OSRuijie Rg-eap602 Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_networkId_merge.lua. | |
| Analizada | Alta (8.8) | 2.4% | — | Ruijie Rg-bcr600w Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the check_changes in file /usr/lib/lua/luci/controller/admin/common.lua. | |
| Analizada | Alta (8.8) | 2.8% | — | Ruijie Rg-ew1300g FirmwareRuijie Be50 Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1.00/V2.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect.lua. | |
| Analizada | Alta (8.8) | 2.8% | — | Ruijienetworks Reyee OSRuijie Rg-rap2200(e) Firmware | 11/12/2025 | 17/6/2026 | OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua. | |
| Modificada | Alta (7.2) | 6.7% | — | Ruijie Rg-ap720-l Firmware | 8/12/2025 | 5/7/2026 | Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint. | |
| Aplazada | Crítica (9.3) | 0.62% | — | Ruijie NBRAI | 24/11/2025 | 17/6/2026 | Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or… | |
| Aplazada | Crítica (9.2) | 0.75% | — | Ruijie Gateway EGAIRuijie NBRAI | 7/11/2025 | 17/6/2026 | Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management system that can be abused via front-end functionality. Attackers can exploit front-end code when features such as guest authentication, local server authentication, or… | |
| Aplazada | Alta (8.6) | 0.60% | — | Ruijienetworks Rg-est300AI | 16/10/2025 | 17/6/2026 | Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the manual, and enabled in the initial configuration. Anyone with the knowledge of the related credentials can log in to the affected device, leading to information disclosure, altering the system… |