Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)6.9%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+236/5/202417/6/2026
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/IPV6/naborTable/add_commit.php. The manipulation of the argument ip_addr/mac_addr leads to os command injection. The attack can be launched remotely.…
AnalizadaAlta (7.2)7.1%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+236/5/202417/6/2026
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown function of the file /view/IPV6/ipv6StaticRoute/static_route_edit_ipv6.php. The manipulation of the argument oldipmask/oldgateway/olddevname leads to os command injection. It is possible to launch the…
AnalizadaAlta (7.2)7.9%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+236/5/202417/6/2026
A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown processing of the file /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php. The manipulation of the argument text_prefixlen/text_gateway/devname leads to os command injection. The attack may be…
AnalizadaAlta (7.2)7.6%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+235/5/202417/6/2026
A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated…
AnalizadaAlta (7.2)6.8%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+235/5/202417/6/2026
A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240428. This affects an unknown part of the file /view/IPV6/ipv6Addr/ip_addr_add_commit.php. The manipulation of the argument prelen/ethname leads to os command injection. It is possible to initiate the attack remotely. The exploit…
AnalizadaAlta (7.2)6.7%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+235/5/202417/6/2026
A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of the file /view/HAconfig/baseConfig/commit.php. The manipulation of the argument peer_ip/local_ip leads to os command injection. The attack may be launched remotely.…
AnalizadaAlta (7.2)6.8%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+235/5/202417/6/2026
A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. The manipulation of the argument interface_from leads to os command injection. The attack can be launched remotely. The…
AnalizadaAlta (7.2)6.8%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+235/5/202417/6/2026
A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function of the file /view/dhcp/dhcpClient/dhcp_client_commit.php. The manipulation of the argument ifName leads to os command injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaAlta (7.2)6.8%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+235/5/202417/6/2026
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknown processing of the file /view/bugSolve/captureData/commit.php. The manipulation of the argument tcpDump leads to os command injection. The attack may be initiated remotely. The exploit has been…
AnalizadaAlta (7.2)5.0%—Ruijie Rg-uac 6000-cc FirmwareRuijie Rg-uac 6000-e10 FirmwareRuijie Rg-uac 6000-e10c FirmwareRuijie Rg-uac 6000-e20 Firmware+2327/4/202417/6/2026
A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects some unknown processing of the file /view/network Config/GRE/gre_edit_commit.php. The manipulation of the argument name leads to os command injection. The attack may be initiated remotely. The exploit…
AnalizadaMedia (6.8)0.57%—Totolink Ex200 Firmware18/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.
AnalizadaBaja (2.4)0.49%—Totolink Ex200 Firmware18/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.
AnalizadaAlta (7.5)55%—Totolink Ex200 Firmware8/4/202417/6/2026
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
AnalizadaAlta (7.5)2.7%—Totolink Ex200 Firmware8/4/202417/6/2026
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.
AnalizadaCrítica (9.1)0.58%—Totolink Ex200 Firmware8/4/202417/6/2026
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
AnalizadaAlta (8.8)8.3%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.
AnalizadaAlta (8.4)0.20%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.
AnalizadaMedia (6.5)0.34%—Totolink Ex200 Firmware8/4/202417/6/2026
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.
AnalizadaAlta (8)0.97%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.
AnalizadaAlta (8.8)0.98%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.
AnalizadaAlta (8.8)0.93%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
AnalizadaCrítica (9.8)1.4%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.
AnalizadaMedia (6.5)0.39%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.
AnalizadaMedia (6.5)0.50%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.
ModificadaCrítica (9.8)1.1%—Netgear Cbr40 FirmwareNetgear Lax20 FirmwareNetgear Mk62 FirmwareNetgear Mr60 Firmware+111/9/202317/6/2026
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
Orbitaley — Vulnerabilidades