Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 6.9% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 6/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/IPV6/naborTable/add_commit.php. The manipulation of the argument ip_addr/mac_addr leads to os command injection. The attack can be launched remotely.… | |
| Analizada | Alta (7.2) | 7.1% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 6/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown function of the file /view/IPV6/ipv6StaticRoute/static_route_edit_ipv6.php. The manipulation of the argument oldipmask/oldgateway/olddevname leads to os command injection. It is possible to launch the… | |
| Analizada | Alta (7.2) | 7.9% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 6/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown processing of the file /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php. The manipulation of the argument text_prefixlen/text_gateway/devname leads to os command injection. The attack may be… | |
| Analizada | Alta (7.2) | 7.6% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240428. This affects an unknown part of the file /view/IPV6/ipv6Addr/ip_addr_add_commit.php. The manipulation of the argument prelen/ethname leads to os command injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Alta (7.2) | 6.7% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of the file /view/HAconfig/baseConfig/commit.php. The manipulation of the argument peer_ip/local_ip leads to os command injection. The attack may be launched remotely.… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. The manipulation of the argument interface_from leads to os command injection. The attack can be launched remotely. The… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function of the file /view/dhcp/dhcpClient/dhcp_client_commit.php. The manipulation of the argument ifName leads to os command injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (7.2) | 6.8% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 5/5/2024 | 17/6/2026 | A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknown processing of the file /view/bugSolve/captureData/commit.php. The manipulation of the argument tcpDump leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.2) | 5.0% | — | Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+23 | 27/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects some unknown processing of the file /view/network Config/GRE/gre_edit_commit.php. The manipulation of the argument name leads to os command injection. The attack may be initiated remotely. The exploit… | |
| Analizada | Media (6.8) | 0.57% | — | Totolink Ex200 Firmware | 18/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function. | |
| Analizada | Baja (2.4) | 0.49% | — | Totolink Ex200 Firmware | 18/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function. | |
| Analizada | Alta (7.5) | 55% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg. | |
| Analizada | Alta (7.5) | 2.7% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg. | |
| Analizada | Crítica (9.1) | 0.58% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh | |
| Analizada | Alta (8.8) | 8.3% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function. | |
| Analizada | Alta (8.4) | 0.20% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default. | |
| Analizada | Media (6.5) | 0.34% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig. | |
| Analizada | Alta (8) | 0.97% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function. | |
| Analizada | Alta (8.8) | 0.98% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function. | |
| Analizada | Alta (8.8) | 0.93% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function. | |
| Analizada | Crítica (9.8) | 1.4% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function. | |
| Analizada | Media (6.5) | 0.39% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization. | |
| Analizada | Media (6.5) | 0.50% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netgear Cbr40 FirmwareNetgear Lax20 FirmwareNetgear Mk62 FirmwareNetgear Mr60 Firmware+11 | 1/9/2023 | 17/6/2026 | Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd. |