Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 20% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded gestiontelebucaramanga / t3l3buc4r4m4ng42013 credentials for an ISP. | |
| Modificada | Crítica (9.8) | 24% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded adminpldt / z6dUABtl270qRxt7a2uGTiw credentials for an ISP. | |
| Modificada | Crítica (9.8) | 24% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded telecomadmin / nE7jA%5m credentials for an ISP. | |
| Modificada | Crítica (9.8) | 17% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / admin credentials for an ISP. | |
| Modificada | Crítica (9.8) | 20% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / CUadmin credentials for an ISP. | |
| Modificada | Crítica (9.8) | 24% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / lnadmin credentials for an ISP. | |
| Modificada | Crítica (9.8) | 21% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded f~i!b@e#r$h%o^m*esuperadmin / s(f)u_h+g|u credentials for an ISP. | |
| Modificada | Crítica (9.8) | 16% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / user1234 credentials for an ISP. | |
| Modificada | Alta (7.5) | 16% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done over HTTPS, using a hardcoded private key that has 0777 permissions. | |
| Modificada | Crítica (9.8) | 16% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. Credentials in /fhconf/umconfig.txt are obfuscated via XOR with the hardcoded *j7a(L#yZ98sSd5HfSgGjMj8;Ss;d)(*&^#@$a2s0i3g key. (The webs binary has details on how XOR is used.) | |
| Modificada | Alta (7.5) | 19% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to find passwords and authentication cookies stored in cleartext in the web.log HTTP logs. | |
| Modificada | Alta (7.5) | 16% | — | Fiberhome Hg6245d Firmware | 10/2/2021 | 17/6/2026 | An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to extract information from the device without authentication by disabling JavaScript and visiting /info.asp. | |
| Modificada | Media (5.4) | 0.86% | — | Gofiber Fiber | 20/7/2020 | 17/6/2026 | In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an attacker could upload a custom filename and then give the link to the victim. With this filename, the attacker can change… | |
| Modificada | Media (5.4) | 1.1% | 💥 Exploit | Fiberhomegroup An5506-04-f Firmware | 31/12/2019 | 17/6/2026 | FiberHome an5506-04-f RP2669 devices have XSS. | |
| Modificada | Alta (8.8) | 5.9% | — | Fiberhome Hg2201t Firmware | 8/10/2019 | 17/6/2026 | /var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution. | |
| Modificada | Alta (7.5) | 11% | — | Fiberhome Hg2201t Firmware | 8/10/2019 | 17/6/2026 | /var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files. | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | UI Airmax AC FirmwareUI Airmax M XM FirmwareUI Airmax M XW FirmwareUI Airmax M TI Firmware+8 | 5/9/2018 | 17/6/2026 | The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in… | |
| Modificada | Crítica (9.8) | 6.1% | — | Fiberhome Vdsl2 Modem HG 150-ub Firmware | 4/4/2018 | 17/6/2026 | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request. | |
| Modificada | Crítica (9.8) | 14% | 💥 Exploit | Fiberhome Vdsl2 Modem HG 150-ub Firmware | 4/4/2018 | 17/6/2026 | FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header. | |
| Modificada | Crítica (9.8) | 37% | 💥 Exploit | Fiberhome Lm53q1 Firmware | 12/1/2018 | 17/6/2026 | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password. | |
| Modificada | Alta (8.8) | 7.1% | 💥 Exploit | Fiberhome Lm53q1 Firmware | 12/1/2018 | 17/6/2026 | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal. | |
| Modificada | Crítica (9.8) | 33% | 💥 Exploit | Fiberhome Lm53q1 Firmware | 12/1/2018 | 17/6/2026 | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version of device, Firmware ID, Connected users… | |
| Modificada | Alta (7.5) | 27% | 💥 Exploit | Routerfiberhome Firmware | 19/10/2017 | 17/6/2026 | On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value. | |
| Modificada | Crítica (9.8) | 66% | 💥 Exploit | Fiberhome Adsl An1020-25 Firmware | 7/9/2017 | 17/6/2026 | An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. Due to improper authentication on this page, the software accepts… | |
| Modificada | Alta (7.3) | 0.81% | — | Ceragon Fiberair Ip-10 Firmware | 21/5/2017 | 17/6/2026 | Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the mateidu account (a hidden user account established by the vendor). This account can be accessed via both the web interface and SSH. In the web interface, this simply grants an attacker read-only access to the device's… |