Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)20%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP.
ModificadaCrítica (9.8)24%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP.
ModificadaCrítica (9.8)24%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP.
ModificadaCrítica (9.8)17%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP.
ModificadaCrítica (9.8)20%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP.
ModificadaCrítica (9.8)24%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP.
ModificadaCrítica (9.8)21%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP.
ModificadaCrítica (9.8)16%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP.
ModificadaAlta (7.5)16%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions.
ModificadaCrítica (9.8)16%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has details on how XOR is used.)
ModificadaAlta (7.5)19%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs.
ModificadaAlta (7.5)16%—Fiberhome Hg6245d Firmware10/2/202117/6/2026
An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp.
ModificadaMedia (5.4)0.86%—Gofiber Fiber20/7/202017/6/2026
In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an attacker could upload a custom filename and then give the link to the victim. With this filename, the attacker can change…
ModificadaMedia (5.4)1.1%💥 ExploitFiberhomegroup An5506-04-f Firmware31/12/201917/6/2026
FiberHome an5506-04-f RP2669 devices have XSS.
ModificadaAlta (8.8)5.9%—Fiberhome Hg2201t Firmware8/10/201917/6/2026
/var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution.
ModificadaAlta (7.5)11%—Fiberhome Hg2201t Firmware8/10/201917/6/2026
/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.
ModificadaCrítica (9.8)74%💥 ExploitUI Airmax AC FirmwareUI Airmax M XM FirmwareUI Airmax M XW FirmwareUI Airmax M TI Firmware+85/9/201817/6/2026
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in…
ModificadaCrítica (9.8)6.1%—Fiberhome Vdsl2 Modem HG 150-ub Firmware4/4/201817/6/2026
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
ModificadaCrítica (9.8)14%💥 ExploitFiberhome Vdsl2 Modem HG 150-ub Firmware4/4/201817/6/2026
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
ModificadaCrítica (9.8)37%💥 ExploitFiberhome Lm53q1 Firmware12/1/201817/6/2026
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password.
ModificadaAlta (8.8)7.1%💥 ExploitFiberhome Lm53q1 Firmware12/1/201817/6/2026
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.
ModificadaCrítica (9.8)33%💥 ExploitFiberhome Lm53q1 Firmware12/1/201817/6/2026
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version of device, Firmware ID, Connected users…
ModificadaAlta (7.5)27%💥 ExploitRouterfiberhome Firmware19/10/201717/6/2026
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
ModificadaCrítica (9.8)66%💥 ExploitFiberhome Adsl An1020-25 Firmware7/9/201717/6/2026
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. Due to improper authentication on this page, the software accepts…
ModificadaAlta (7.3)0.81%—Ceragon Fiberair Ip-10 Firmware21/5/201717/6/2026
Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the mateidu account (a hidden user account established by the vendor). This account can be accessed via both the web interface and SSH. In the web interface, this simply grants an attacker read-only access to the device's…
Orbitaley — Vulnerabilidades