Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)1.6%—H3C Magic Nx15 FirmwareH3C Magic Nx30 PRO FirmwareH3C Magic Nx400 FirmwareH3C Magic R3010 Firmware+114/4/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler.…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+114/4/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/setLanguage of the component HTTP POST Request Handler. The manipulation leads…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+114/4/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getCapabilityWeb of the component HTTP POST Request Handler. The manipulation…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI14/4/202517/6/2026
A vulnerability has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014 and classified as critical. This vulnerability affects the function FCGI_WizardProtoProcess of the file /api/wizard/setsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx400AIH3C Magic R3010AI14/4/202517/6/2026
A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014. This affects the function FCGI_WizardProtoProcess of the file /api/wizard/getsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI13/4/202517/6/2026
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this issue is the function FCGI_WizardProtoProcess of the file /api/wizard/getSpecs of the component HTTP POST Request Handler. The manipulation leads to command…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI13/4/202517/6/2026
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this vulnerability is the function FCGI_WizardProtoProcess of the file /api/wizard/getCapability of the component HTTP POST Request Handler. The manipulation leads to command…
AplazadaAlta (8.6)1.1%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+113/4/202517/6/2026
A vulnerability classified as critical has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getBasicInfo of the component HTTP POST Request Handler. The manipulation leads to…
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the component HTTP POST Request Handler. The manipulation leads to…
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of the component HTTP POST Request Handler. The manipulation leads…
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to command injection. The…
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST Request Handler. The manipulation leads to command injection. The…
AplazadaAlta (8.6)1.0%—H3C Magic Nx30 PROAIH3C Magic Nx400AI25/3/202517/6/2026
A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack needs to be approached within the local network. It is recommended to…
AplazadaAlta (8.6)1.0%—H3C Magic Nx30 PROAI25/3/202517/6/2026
A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file /api/wizard/getNetworkStatus of the component HTTP POST Request Handler. The manipulation leads to command injection. Access to the local network is required for this attack to…
AplazadaAlta (8.6)1.0%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTTP POST Request Handler. The manipulation leads to command…
AplazadaAlta (8.6)8.3%—H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+125/3/202517/6/2026
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The manipulation leads to command injection.…
AplazadaMedia (5.1)0.25%—H3C Fa3010lAI11/2/202517/6/2026
Buffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which is related to the setting of firewall rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
ModificadaCrítica (9.8)0.76%—H3C N12 Firmware14/1/20255/7/2026
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.
ModificadaCrítica (9.8)0.76%—H3C N12 Firmware14/1/20255/7/2026
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.
ModificadaCrítica (9.8)0.55%—H3C N12 Firmware14/1/20255/7/2026
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.
ModificadaCrítica (9.8)0.55%—H3C N12 Firmware14/1/20255/7/2026
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.
ModificadaCrítica (9.8)0.76%—H3C N12 Firmware14/1/20255/7/2026
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.
AplazadaAlta (7.5)0.31%—H3C S1526AI17/12/202417/6/2026
An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.
ModificadaCrítica (9.8)12%—H3C Gr-1800ax Firmware20/11/202417/6/2026
H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.
AnalizadaCrítica (9.8)0.56%—H3C Gr1100-p Firmware16/8/202417/6/2026
H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.
Orbitaley — Vulnerabilidades