Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

81 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.58%—Cypress Cyw920735q60evb-01 FirmwareCypress Cyw20735b1 Firmware7/9/202117/6/2026
The Bluetooth Classic implementation in the Cypress CYW920735Q60EVB does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and restart (crash) of the device by flooding it with LMP_AU_Rand packets after the paging procedure.
ModificadaAlta (7.5)2.2%—Asus Zenwifi AX (xt8) FirmwareAsus Rt-ax3000 FirmwareAsus Rt-ax55 FirmwareAsus Rt-ax56u Firmware+2312/4/202117/6/2026
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a…
ModificadaAlta (7.5)2.9%💥 PoCAsus Dsl-n14u B1 Firmware18/1/202117/6/2026
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename Settings_DSL-N14U-B1.trx is used. Once this file is loaded, shutdown measures on a wide range of services are triggered as if it were a real update, resulting in a…
ModificadaCrítica (9.8)1.6%—Dlink Dir-600 B1 FirmwareDlink Dir-615 J1 FirmwareDlink Dir-645 A1 FirmwareDlink Dir-815 A1 Firmware+311/11/201917/6/2026
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00.
ModificadaCrítica (9.8)56%💥 ExploitDlink Dir-868l B1 FirmwareDlink Dir-817lw A1 Firmware11/10/201917/6/2026
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used…
ModificadaCrítica (9.8)5.6%—Patlite Nbm-d88n FirmwarePatlite Nhl-3fb1 FirmwarePatlite Nhl-3fv1n Firmware21/3/201917/6/2026
A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or "kamiyo4" password to the _secret1.htm URI.…
ModificadaAlta (7.5)1.9%💥 PoCD-link Dcs-936l FirmwareDlink Dcs-942l FirmwareD-link Dcs-8000lh FirmwareD-link Dcs-942lb1 Firmware+1420/12/201817/6/2026
D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many…
ModificadaCrítica (9.8)5.2%—Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+1015/10/201817/6/2026
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution
ModificadaCrítica (9.8)5.4%—Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+1015/10/201817/6/2026
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a…
ModificadaCrítica (9.8)2.3%—Telesquare Sdt-cs3b1 FirmwareTelesquare Sdt-cw3b1 Firmware21/6/201817/6/2026
Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account.
ModificadaCrítica (9.8)4.2%—Asus Rt-ac51u FirmwareAsus Rt-ac58u FirmwareAsus Rt-ac66u FirmwareAsus Rt-ac1750 Firmware+920/4/201817/6/2026
ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3.0.0.4.382.50276; RT-AC86U and RT-AC2900 routers with firmware…
ModificadaMedia (6.5)1.0%—Asus Dsl-ac51 FirmwareAsus Dsl-ac52u FirmwareAsus Dsl-ac55u FirmwareAsus Dsl-n55u C1 Firmware+1229/1/201817/6/2026
Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote authenticated users to read…
ModificadaCrítica (9.8)1.3%—Asus Dsl-ac51 FirmwareAsus Dsl-ac52u FirmwareAsus Dsl-ac55u FirmwareAsus Dsl-n55u C1 Firmware+1229/1/201817/6/2026
ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote attackers to change passwords of arbitrary users via the http_passwd parameter to mod_login.asp.
ModificadaBaja (3.7)1.5%—Seil B1 FirmwareSeil BPV 4 FirmwareSeil X1 FirmwareSeil X2 Firmware+115/9/201717/6/2026
SEIL/X 4.60 to 5.72, SEIL/B1 4.60 to 5.72, SEIL/x86 3.20 to 5.72, SEIL/BPV4 5.00 to 5.72 allows remote attackers to cause a temporary failure of the device's encrypted communications via a specially crafted packet.
ModificadaCrítica (9.8)39%💥 ExploitDlink Dir-600 B1 Firmware18/8/201717/6/2026
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password.
ModificadaCrítica (9.8)5.6%—Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+2418/7/201717/6/2026
Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100,…
ModificadaAlta (7.8)1.8%—Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+2417/7/201717/6/2026
Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200,…
ModificadaAlta (7.8)2.8%—Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+2417/7/201717/6/2026
Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200,…
ModificadaAlta (7.5)1.5%—Seil X86 Fuji FirmwareSeil BPV 4 FirmwareSeil X1 FirmwareSeil X2 Firmware+128/4/201717/6/2026
SEIL/x86 Fuji 1.70 to 5.62, SEIL/BPV4 5.00 to 5.62, SEIL/X1 1.30 to 5.62, SEIL/X2 1.30 to 5.62, SEIL/B1 1.00 to 5.62 allows remote attackers to cause a denial of service via specially crafted IPv4 UDP packets.
ModificadaAlta (8.1)3.3%—D-link Dap-1353 H/W B1 FirmwareD-link Dap-2553 H/W A1 FirmwareD-link Dap-3520 H/W A1 Firmware21/4/201717/6/2026
D-Link DAP-1353 H/W vers. B1 3.15 and earlier, D-Link DAP-2553 H/W ver. A1 1.31 and earlier, and D-Link DAP-3520 H/W ver. A1 1.16 and earlier reveal wireless passwords and administrative usernames and passwords over SNMP.
ModificadaAlta (7.1)1.5%—IIJ Seil X86 Fuji FirmwareIIJ Seil/x2 FirmwareIIJ Seil/x1 FirmwareIIJ Seil/b1 Firmware+128/2/201517/6/2026
npppd in the PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 Fuji routers 1.00 through 3.30, SEIL/X1 routers 3.50 through 4.70, SEIL/X2 routers 3.50 through 4.70, and SEIL/B1 routers 3.50 through 4.70 allows remote attackers to cause a denial of service (infinite loop and device hang) via a crafted SSTP packet.
ModificadaAlta (7.8)1.8%—IIJ Seil Plus FirmwareIIJ Seil PlusIIJ Seil B1 FirmwareIIJ Seil X1 Firmware+45/12/201417/6/2026
The (1) PPP Access Concentrator (PPPAC) and (2) Dial-Up Networking Internet Initiative Japan Inc. SEIL series routers SEIL/x86 Fuji 1.00 through 3.22; SEIL/X1, SEIL/X2, and SEIL/B1 1.00 through 4.62; SEIL/Turbo 1.82 through 2.18; and SEIL/neu 2FE Plus 1.82 through 2.18 allow remote attackers to cause a denial of…
ModificadaAlta (7.5)3.2%—IIJ Seil B1 FirmwareIIJ Seil X2 FirmwareIIJ Seil X1 FirmwareIIJ Seil X86 Fuji Firmware5/12/201417/6/2026
Internet Initiative Japan Inc. SEIL Series routers SEIL/X1 2.50 through 4.62, SEIL/X2 2.50 through 4.62, SEIL/B1 2.50 through 4.62, and SEIL/x86 Fuji 1.70 through 3.22 allow remote attackers to cause a denial of service (CPU and traffic consumption) via a large number of NTP requests within a short time, which causes…
ModificadaMedia (5)2.1%—IIJ Seil%2fturbo FirmwareIIJ Seil/turboIIJ Seil%2fneu 2FE Plus FirmwareIIJ Seil/neu 2FE Plus+816/6/201417/6/2026
The PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 routers 1.00 through 3.10, SEIL/X1 routers 1.00 through 4.50, SEIL/X2 routers 1.00 through 4.50, SEIL/B1 routers 1.00 through 4.50, SEIL/Turbo routers 1.80 through 2.17, and SEIL/neu 2FE Plus routers 1.80 through 2.17 allows remote attackers to cause a denial of…
ModificadaMedia (4)1.3%—IIJ Seil%2fx1 FirmwareIIJ Seil/x1IIJ Seil%2fb1 FirmwareIIJ Seil/b1+81/10/201316/6/2026
The PPP Access Concentrator (PPPAC) in Internet Initiative Japan Inc. SEIL/x86 1.00 through 2.80, SEIL/X1 1.00 through 4.30, SEIL/X2 1.00 through 4.30, SEIL/B1 1.00 through 4.30, SEIL/Turbo 1.80 through 2.15, and SEIL/neu 2FE Plus 1.80 through 2.15 generates predictable random numbers, which allows remote attackers to…