Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+368 | 6/8/2025 | 17/6/2026 | Transient DOS while processing an ANQP message. | |
| Analizada | Alta (7.5) | 0.21% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+146 | 6/8/2025 | 17/6/2026 | Transient DOS while processing a frame with malformed shared-key descriptor. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+345 | 6/8/2025 | 17/6/2026 | Information disclosure while processing the hash segment in an MBN file. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm Qcm4490 FirmwareQualcomm Qcm5430 FirmwareQualcomm Qcm6125 FirmwareQualcomm Qcm6490 Firmware+338 | 6/8/2025 | 17/6/2026 | Information disclosure while reading data from an image using specified offset and size parameters. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+340 | 8/7/2025 | 17/6/2026 | Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. | |
| Analizada | Alta (7.5) | 0.23% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+207 | 8/7/2025 | 17/6/2026 | Transient DOS while handling beacon frames with invalid IE header length. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+340 | 8/7/2025 | 17/6/2026 | Memory corruption while processing video packets received from video firmware. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 214 FirmwareQualcomm Immersive Home 216 Firmware+236 | 8/7/2025 | 17/6/2026 | Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. | |
| Analizada | Crítica (9.8) | 11% | — | B-link Bl-wr9000 FirmwareB-link Bl-ac1900 FirmwareB-link Bl-ac2100 AZ3 FirmwareB-link Bl-x10 AC8 Firmware+5 | 13/6/2025 | 17/6/2026 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the cmd parameter in the bs_SetCmd function. | |
| Analizada | Crítica (9.8) | 1.9% | — | B-link Bl-wr9000 FirmwareB-link Bl-ac2100 AZ3 FirmwareB-link Bl-lte300 FirmwareB-link Bl-f1200 AT1 Firmware+3 | 13/6/2025 | 17/6/2026 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bs_SetDNSInfo function. | |
| Analizada | Crítica (9.8) | 1.6% | — | B-link Bl-x10 AC8 FirmwareB-link Bl-lte300 FirmwareB-link Bl-wr9000 FirmwareB-link Bl-ac2100 AZ3 Firmware+4 | 13/6/2025 | 17/6/2026 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 werediscovered to contain a command injection vulnerability via the mac parameter in the bs_SetMacBlack function. | |
| Analizada | Crítica (9.8) | 6.9% | 💥 Exploit | B-link Bl-wr9000 FirmwareB-link Bl-ac2100 AZ3 FirmwareB-link Bl-x10 AC8 FirmwareB-link Bl-lte300 Firmware+4 | 13/6/2025 | 17/6/2026 | Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain a command injection vulnerability via the bs_SetSSIDHide function. | |
| Analizada | Crítica (9.8) | 1.6% | — | B-link Bl-wr9000 FirmwareB-link Bl-ac1900 FirmwareB-link Bl-ac2100 AZ3 FirmwareB-link Bl-x10 AC8 Firmware+5 | 13/6/2025 | 17/6/2026 | Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT1 V1.0.0, BL-X26_AC8 V1.2.8, BLAC450M_AE4 V4.0.0 and BL-X26_DA3 V1.2.7 were discovered to contain a command injection vulnerability via the routepwd parameter in the sub_45B238 function. | |
| Analizada | Alta (7.5) | 0.24% | — | Qualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform FirmwareQualcomm Ipq5300 Firmware+63 | 3/6/2025 | 17/6/2026 | Transient DOS while processing the tone measurement response buffer when the response buffer is out of range. | |
| Analizada | Alta (7.5) | 0.23% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+207 | 3/6/2025 | 17/6/2026 | Transient DOS while processing the EHT operation IE in the received beacon frame. | |
| Analizada | Media (5.3) | 31% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function ssid1MACFilter of the file /goform/ssid1MACFilter. The manipulation of the argument… | |
| Analizada | Media (5.3) | 14% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. This affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. The manipulation of the argument pwd leads… | |
| Analizada | Media (5.3) | 14% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RP_checkFWByBBS of the file /goform/RP_checkFWByBBS. The manipulation of the argument… | |
| Analizada | Media (5.3) | 14% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this vulnerability is the function RP_UpgradeFWByBBS of the file /goform/RP_UpgradeFWByBBS. The manipulation of the argument… | |
| Analizada | Media (5.3) | 14% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function wirelessAdvancedHidden of the file /goform/wirelessAdvancedHidden. The manipulation of the argument… | |
| Analizada | Media (5.3) | 14% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_pingGatewayByBBS of the file /goform/RP_pingGatewayByBBS. The manipulation of the argument ip/nm/gw… | |
| Analizada | Media (5.3) | 14% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setDeviceURL of the file /goform/setDeviceURL. The manipulation of the argument DeviceURL leads to os command… | |
| Analizada | Media (5.3) | 5.0% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function NTP of the file /goform/NTP. The manipulation of the argument… | |
| Analizada | Media (5.3) | 5.0% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been rated as critical. Affected by this issue is the function verifyFacebookLike of the file /goform/verifyFacebookLike. The manipulation of the argument… | |
| Analizada | Media (5.3) | 26% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. Affected by this vulnerability is the function WPS of the file /goform/WPS. The manipulation of the argument PIN leads to command injection.… |