Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetIsp param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetMask param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetAutoFocus param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetLocalLink param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetEmail param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetFtp param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetNtp param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetNetPort param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetUpnp param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetDevName param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetWifi param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetPush param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetCloudSchedule param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Set3G param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetNorm param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetCrop param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.7) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetRec param is not object. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to a reboot. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (8.2) | 1.1% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.8% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Media (5.9) | 0.89% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.91% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A denial of service vulnerability exists in the cgiserver.cgi API command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of HTTP requests can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.2% | — | Reolink Rlc-410w Firmware | 28/1/2022 | 17/6/2026 | A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequence of requests to trigger this vulnerability. |