Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

131 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.21%—Reolink Smart 2K Plug-in Wi-fi Video Doorbell With ChimeAI22/8/202517/6/2026
Insecure permissions in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allow attackers to arbitrarily change other users' passwords via manipulation of the userName value.
AplazadaMedia (5.3)0.24%—Reolink Smart 2K+ Plug-in Wi-fi Video Doorbell With ChimeAI22/8/202517/6/2026
Insufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows authenticated attackers to create accounts with elevated privileges.
AplazadaMedia (5.3)0.24%—Reolink Smart 2K Plus Plug IN WI FI Video Doorbell With ChimeAI22/8/202517/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to access the Admin-only settings and edit the session storage.
AplazadaCrítica (9.4)87%💥 ExploitShenzhen Aitemi M300 Wi-fi RepeaterAI7/8/202517/6/2026
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points,…
ModificadaAlta (7.8)0.15%💥 PoCAziot 2MP Full HD Smart Wi-fi Cctv Home Security Camera Firmware30/7/20255/7/2026
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in…
AplazadaCrítica (9.3)0.38%—Art-in Bilisim Teknolojileri VE Yazilim Hizm. Tic. Ltd. STI Wi-fi Cloud HotspotAI24/6/202517/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm. Tic. Ltd. Şti. Wi-Fi Cloud Hotspot allows Authentication Abuse, Authentication Bypass. This issue affects Wi-Fi Cloud Hotspot: before 30.05.2025.
AplazadaAlta (7.3)0.32%—Prolink 4G LTE Mobile Wi-fi Dl-7203eAI3/2/202517/6/2026
Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter.
AplazadaMedia (6.3)0.28%—Prolink 4G LTE Mobile Wi-fi Dl-7203eAI3/2/202517/6/2026
Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the browser to execute…
AplazadaAlta (7.2)1.2%—Home 5G Hr02AIHome Wi-fi Station Sh-54cAI23/12/202417/6/2026
home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command may be executed with the root privilege by an administrative user.
AplazadaMedia (5.3)0.58%—Home 5G Hr02AIWi-fi Station SH 52BAIWi-fi Station SH 54CAI23/12/202417/6/2026
home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug function. A remote unauthenticated attacker may get the web console of the product down.
AplazadaAlta (7.2)1.2%—Home 5G Hr02AIWi-fi Station Sh-52bAIWi-fi Station Sh-54cAI23/12/202417/6/2026
home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An arbitrary OS command may be executed with the root privilege by an administrative user.
AplazadaBaja (3.5)0.21%—Tp-link Mesh Wi-fi Router Rp562bAI12/11/202417/6/2026
Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain information of the other devices connected through the Wi-Fi.
AplazadaMedia (4.6)0.20%—Mesh Wi-fi Router Rp562bAI12/11/202417/6/2026
Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may obtain or alter the settings of the device .
AplazadaAlta (8.8)2.5%💥 PoCWi-fi Alliance Wi-fi Test SuiteAIArcadyan Fmimg51ax000jAI11/11/202417/6/2026
Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On…
AplazadaMedia (5.4)0.46%—CP Plus Wi-fi CameraAI8/4/202417/6/2026
A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability is an unknown functionality of the component User Management. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and…
AplazadaBaja (2.3)0.39%—Intel Proset WirelessAIIntel Killer WI FIAI14/2/202417/6/2026
Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
ModificadaAlta (7.5)0.78%—Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+510/10/202317/6/2026
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a…
ModificadaAlta (8.8)0.81%—Cambiumnetworks Enterprise Wi-fi29/9/202317/6/2026
Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.
ModificadaMedia (5.9)0.27%—Trendnet Tv-ip651wi Firmware2/2/202317/6/2026
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and…
ModificadaMedia (6.5)0.32%—Intel Wi-fi 6E Ax411 FirmwareIntel Wi-fi 6E Ax211 FirmwareIntel Wi-fi 6E Ax210 FirmwareIntel Wi-fi 6E Ax201 Firmware+1011/11/202217/6/2026
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.5)0.42%—Intel Killer Wifi SoftwareIntel Proset/wireless WifiIntel Uefi Wifi DriverIntel Killer Wi-fi 6 Ax1650 Firmware+33811/11/202217/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access.
ModificadaMedia (4.4)0.22%—Intel Proset Wi-fi 6E Ax210 FirmwareIntel Wi-fi 6E Ax211 FirmwareIntel Wi-fi 6E Ax411 Firmware18/8/202217/6/2026
Out of bounds read for some Intel(R) PROSet/Wireless WiFi products may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)0.35%—Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+518/8/202217/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaAlta (7.5)0.80%—Intel Wireless-ac 9560 FirmwareIntel Wireless-ac 9462 FirmwareIntel Wireless-ac 9461 FirmwareIntel Wireless-ac 9260 Firmware+518/8/202217/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaMedia (6.7)0.21%—Intel Proset Wi-fi 6E Ax210 FirmwareIntel Wi-fi 6E Ax211 FirmwareIntel Wi-fi 6E Ax411 Firmware18/8/202217/6/2026
Out of bounds write for some Intel(R) PROSet/Wireless WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.