Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.36% | — | Tp-link Tapo C520ws Firmware | 2/4/2026 | 24/7/2026 | A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling component due to insufficient input validation. An attacker can exploit this vulnerability by supplying an excessively long value for a vulnerable configuration parameter, resulting in a stack… | |
| Analizada | Alta (8.7) | 0.48% | — | Tp-link Tapo C520ws Firmware | 2/4/2026 | 24/7/2026 | An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent parsing and authorization logic in JSON requests during authentication check. An unauthenticated attacker can append an authentication-exempt action to a… | |
| Analizada | Alta (7.1) | 0.36% | — | Tp-link Tapo C520ws Firmware | 2/4/2026 | 24/7/2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of local video stream content due to insufficient alignment and validation of buffer boundaries when processing streaming inputs.An attacker on the same network segment could trigger heap memory… | |
| Analizada | Alta (7.1) | 0.36% | — | Tp-link Tapo C520ws Firmware | 2/4/2026 | 24/7/2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when appending segmented request bodies without continuous write‑boundary verification, due to insufficient boundary validation when handling externally supplied HTTP input. An attacker on the same… | |
| Modificada | Alta (7.1) | 0.52% | — | Tp-link Tapo C520ws Firmware | 2/4/2026 | 19/8/2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling externally supplied HTTP input. An attacker on… | |
| Analizada | Alta (8.8) | 0.17% | — | IBM Datapower Gateway | 1/4/2026 | 17/6/2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… | |
| Analizada | Media (6.8) | 0.25% | — | IBM Datapower Gateway | 1/4/2026 | 17/6/2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user. | |
| Analizada | Alta (7.7) | 0.23% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel.… | |
| Analizada | Baja (2) | 0.36% | — | Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+10 | 13/2/2026 | 17/6/2026 | A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow… | |
| Modificada | Alta (7.2) | 0.41% | — | Tp-link Tapo C260 Firmware | 10/2/2026 | 17/6/2026 | On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change sensitive configuration parameters without… | |
| Analizada | Alta (8.7) | 22% | — | Tp-link Tapo C260 Firmware | 10/2/2026 | 17/6/2026 | On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device… | |
| Modificada | Media (6.9) | 0.30% | — | Tp-link Tapo C260 Firmware | 10/2/2026 | 4/8/2026 | A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalization fails. An attacker can exploit… | |
| Analizada | Alta (7.5) | 0.20% | — | Tp-link Tapo H100 FirmwareTp-link Tapo P100 Firmware | 5/2/2026 | 17/6/2026 | An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications. This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation… | |
| Analizada | Alta (7.1) | 0.64% | — | Tp-link Tapo C220 FirmwareTp-link Tapo C520ws Firmware | 27/1/2026 | 17/6/2026 | By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can trigger a persistent denial of service, requiring a manual reboot or application initiated restart to… | |
| Modificada | Alta (7.1) | 0.59% | — | Tp-link Tapo C220 FirmwareTp-link Tapo C520ws Firmware | 27/1/2026 | 17/6/2026 | The HTTP parser of Tapo C210 v3, C220 v1 and C520WS v2 cameras improperly handles requests containing an excessively long URL path. An invalid‑URL error path continues into cleanup code that assumes allocated buffers exist, leading to a crash and service restart. An unauthenticated attacker can force repeated service… | |
| Modificada | Alta (7.1) | 0.73% | — | Tp-link Tapo C220 FirmwareTp-link Tapo C520ws Firmware | 27/1/2026 | 17/6/2026 | The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length header. The resulting failed memory allocation triggers a NULL pointer dereference, causing the main service process to crash. An unauthenticated attacker can repeatedly… | |
| Analizada | Alta (7.1) | 0.24% | — | Tp-link Tapo C200 Firmware | 20/12/2025 | 17/6/2026 | The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulting in… | |
| Modificada | Alta (8.7) | 0.53% | — | Tp-link Tapo C200 Firmware | 20/12/2025 | 25/9/2026 | A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized… | |
| Modificada | Alta (8.7) | 0.37% | — | Tp-link Tapo C200 Firmware | 20/12/2025 | 30/9/2026 | The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS). | |
| Aplazada | Alta (7) | 0.19% | — | Tp-link TapoAITp-link Tapo CameraAI | 16/12/2025 | 17/6/2026 | Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo cameras, allowing attackers to brute force the password in the local network. Issue can be mitigated through mobile application updates. Device firmware remains unchanged. | |
| Aplazada | Alta (7) | 0.17% | — | Tp-link Tapo D230s1AI | 30/9/2025 | 17/6/2026 | The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have the physical access to the device. This issue affects Tapo D230S1 V1.20: before 1.2.2 Build 20250907. | |
| Aplazada | Alta (8.6) | 0.35% | — | Home-assistant Tapo ControlAI | 14/8/2025 | 17/6/2026 | HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect users of the Home Assistant integration itself — it only impacts the GitHub Actions… | |
| Aplazada | Media (4.4) | 0.13% | — | Tp-link Tapo H200AI | 9/4/2025 | 17/6/2026 | This vulnerability exists in TP-Link Tapo H200 V1 IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device. | |
| Aplazada | Alta (7) | 0.26% | — | Tp-link Tapo C500AI | 10/2/2025 | 17/6/2026 | This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle… | |
| Analizada | Media (4.4) | 0.13% | — | Tp-link Tapo H100 Firmware | 4/11/2024 | 17/6/2026 | This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device. |