Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)13%—Tp-link Tl-wr841n Firmware24/2/202217/6/2026
TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.
ModificadaCrítica (9.8)0.67%—Tp-link Tl-wr841n Firmware9/2/202217/6/2026
The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in cleartextbase64 format. Successful exploitation of this vulnerability could allow a remote attacker to intercept credentials and subsequently perform administrative…
ModificadaAlta (8.8)42%💥 ExploitTp-link Tl-wr841n Firmware26/1/202117/6/2026
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.
ModificadaAlta (7.2)9.3%💥 PoCTp-link Tl-wr841n Firmware2/4/202017/6/2026
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.
ModificadaAlta (8.8)14%💥 PoCTp-link Tl-wr841n Firmware7/1/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default. When parsing the Host request header, the…
ModificadaAlta (8.8)2.7%—Tp-link Tl-wr841n Firmware2/7/201817/6/2026
The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection.
ModificadaMedia (4.3)0.70%—Tp-link Tl-wr841n Firmware2/7/201817/6/2026
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
ModificadaCrítica (9.8)2.9%—Tp-link Tl-wr841n Firmware2/7/201817/6/2026
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.
ModificadaAlta (8.8)0.46%—Tp-link Tl-wr841n Firmware2/7/201817/6/2026
CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.
ModificadaCrítica (9.8)68%💥 PoCTp-link Tl-wr840n FirmwareTp-link Tl-wr841n Firmware4/6/201817/6/2026
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer:…
AnalizadaAlta (7.5)84%⚠ Explotación activa💥 ExploitTp-link Tl-wr741nd FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n FirmwareTp-link Archer C5 Firmware+722/4/201517/6/2026
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with…
ModificadaMedia (4.3)0.78%—Tp-link Tl-wr841n FirmwareTp-link Tl-wr841n30/9/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to userRpm/NoipDdnsRpm.htm.
ModificadaMedia (4.3)3.5%💥 ExploitTp-link Tl-wr841n FirmwareTp-link Tl-wr841n26/1/201316/6/2026
Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via the URL parameter.
ModificadaAlta (7.8)69%💥 ExploitTp-link Tl-wr841nTp-link Tl-wr841n Firmware1/11/201216/6/2026
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.