Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.74% | — | Tp-link Tl-wr940n V2 FirmwareTp-link Tl-wr941nd V5 FirmwareTp-link Tl-wr841n V8 Firmware | 21/8/2023 | 17/6/2026 | TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Alta (7.5) | 0.81% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr941nd Firmware | 22/6/2023 | 17/6/2026 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/QoSRuleListRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Alta (7.7) | 0.70% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr941nd FirmwareTp-link Tl-wr743nd Firmware | 22/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlAccessTargetsRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Alta (7.7) | 0.80% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr941nd Firmware | 22/6/2023 | 17/6/2026 | An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Alta (7.7) | 0.71% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n FirmwareTp-link Tl-wr941nd Firmware | 22/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read out-of-bounds via the component /userRpm/VirtualServerRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Alta (7.5) | 0.81% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n FirmwareTp-link Tl-wr941nd Firmware | 22/6/2023 | 17/6/2026 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Analizada | Alta (8.8) | 42% | ⚠ Explotación activa💥 PoC | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n Firmware | 7/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . | |
| Modificada | Alta (8.1) | 0.90% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n Firmware | 7/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/FixMapCfgRpm. | |
| Modificada | Alta (8.1) | 0.90% | — | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n Firmware | 7/6/2023 | 17/6/2026 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/WlanMacFilterRpm. | |
| Modificada | Alta (8.8) | 1.0% | — | Tp-link Tl-wr841n FirmwareTp-link Tl-wr841nd V7 Firmware | 20/12/2022 | 17/6/2026 | An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image. | |
| Modificada | Media (6.1) | 0.47% | — | Tp-link Tl-wr841n Firmware | 18/10/2022 | 17/6/2026 | TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Alta (8.8) | 2.0% | 💥 PoC | Tp-link Tl-wr841 FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr841n(eu) Firmware | 14/7/2022 | 9/7/2026 | A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)_V12_160624 and TL-WR841 V11… | |
| Modificada | Crítica (9.8) | 13% | — | Tp-link Tl-wr841n Firmware | 24/2/2022 | 17/6/2026 | TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 0.67% | — | Tp-link Tl-wr841n Firmware | 9/2/2022 | 17/6/2026 | The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in cleartextbase64 format. Successful exploitation of this vulnerability could allow a remote attacker to intercept credentials and subsequently perform administrative… | |
| Modificada | Alta (8.8) | 42% | 💥 Exploit | Tp-link Tl-wr841n Firmware | 26/1/2021 | 17/6/2026 | A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577. | |
| Modificada | Alta (7.2) | 9.3% | 💥 PoC | Tp-link Tl-wr841n Firmware | 2/4/2020 | 17/6/2026 | A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network. | |
| Modificada | Alta (8.8) | 14% | 💥 PoC | Tp-link Tl-wr841n Firmware | 7/1/2020 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default. When parsing the Host request header, the… | |
| Modificada | Alta (8.8) | 2.7% | — | Tp-link Tl-wr841n Firmware | 2/7/2018 | 17/6/2026 | The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection. | |
| Modificada | Media (4.3) | 0.70% | — | Tp-link Tl-wr841n Firmware | 2/7/2018 | 17/6/2026 | TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking. | |
| Modificada | Crítica (9.8) | 2.9% | — | Tp-link Tl-wr841n Firmware | 2/7/2018 | 17/6/2026 | On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request. | |
| Modificada | Alta (8.8) | 0.46% | — | Tp-link Tl-wr841n Firmware | 2/7/2018 | 17/6/2026 | CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices. | |
| Modificada | Crítica (9.8) | 68% | 💥 PoC | Tp-link Tl-wr840n FirmwareTp-link Tl-wr841n Firmware | 4/6/2018 | 17/6/2026 | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer:… | |
| Analizada | Alta (7.5) | 84% | ⚠ Explotación activa💥 Exploit | Tp-link Tl-wr741nd FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n FirmwareTp-link Archer C5 Firmware+7 | 22/4/2015 | 17/6/2026 | Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with… | |
| Modificada | Media (4.3) | 0.78% | — | Tp-link Tl-wr841n FirmwareTp-link Tl-wr841n | 30/9/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to userRpm/NoipDdnsRpm.htm. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Tp-link Tl-wr841n FirmwareTp-link Tl-wr841n | 26/1/2013 | 16/6/2026 | Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via the URL parameter. |