Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.83% | — | Cerberus PRO EN Engineering ToolAICerberus PRO EN Fire Panel Fc72xAICerberus PRO EN X200 Cloud DistributionAICerberus PRO EN X300 Cloud DistributionAI+11 | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions),… | |
| Modificada | Crítica (9.8) | 0.81% | — | Siemens Cerberus PRO EN Engineering ToolSiemens Cerberus PRO EN Fire Panel Fc72xSiemens Cerberus PRO EN X200 Cloud DistributionSiemens Cerberus PRO EN X300 Cloud Distribution+5 | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < IP6 SR3), Cerberus PRO EN Fire Panel FC72x IP7 (All versions < IP7 SR5), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions < V3.0.6602), Cerberus PRO EN X200 Cloud… | |
| Analizada | Alta (7.5) | 24% | 💥 Exploit | Gl-inet Mt6000 FirmwareGl-inet Xe3000 FirmwareGl-inet X3000 FirmwareGl-inet Mt3000 Firmware+22 | 27/2/2024 | 17/6/2026 | An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200… | |
| Analizada | Alta (7.2) | 1.3% | — | Zyxel Atp100 FirmwareZyxel Atp100w FirmwareZyxel Atp200 FirmwareZyxel Atp500 Firmware+38 | 20/2/2024 | 17/6/2026 | A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware… | |
| Modificada | Alta (8.8) | 1.1% | — | Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware+1 | 11/1/2024 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi. | |
| Modificada | Alta (8) | 0.45% | — | Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Archer Axe75 Firmware | 11/1/2024 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands. | |
| Modificada | Alta (8.8) | 0.53% | — | Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware | 11/1/2024 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings. | |
| Modificada | Media (6.8) | 0.86% | — | Elecom Wrc-x3000gsn FirmwareElecom Wrc-x3000gs FirmwareElecom Wrc-x3000gsa Firmware | 12/12/2023 | 17/6/2026 | OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the product. | |
| Modificada | Alta (8) | 1.00% | — | Elecom Wrc-x3000gs2-w FirmwareElecom Wrc-x3000gs2-b FirmwareElecom Wrc-x3000gs2a-b Firmware | 16/11/2023 | 17/6/2026 | OS command injection vulnerability in WRC-X3000GS2-W v1.05 and earlier, WRC-X3000GS2-B v1.05 and earlier, and WRC-X3000GS2A-B v1.05 and earlier allows a network-adjacent authenticated user to execute an arbitrary OS command by sending a specially crafted request. | |
| Modificada | Media (5.3) | 0.27% | — | Asus Rt-ax3000 Firmware | 13/6/2023 | 17/6/2026 | ASUS Router RT-AX3000 Firmware versions prior to 3.0.0.4.388.23403 uses sensitive cookies without 'Secure' attribute. When an attacker is in a position to be able to mount a man-in-the-middle attack, and a user is tricked to log into the affected device through an unencrypted ('http') connection, the user's session… | |
| Modificada | Crítica (9.8) | 14% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer. | |
| Modificada | Media (4.9) | 3.9% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters… | |
| Modificada | Alta (7.5) | 0.94% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 10/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the… | |
| Modificada | Alta (7.5) | 30% | 💥 Exploit | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key. | |
| Modificada | Alta (7.5) | 0.82% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to obtain a list of files in a specific directory, by using the regex feature in a package name. | |
| Modificada | Alta (7.5) | 20% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. | |
| Modificada | Alta (8.8) | 1.2% | — | Netgear Nighthawk Ax1800 FirmwareNetgear Nighthawk Ax2400 FirmwareNetgear Nighthawk Ax3000 FirmwareNetgear Nighthawk Ax5400 Firmware+2 | 16/12/2022 | 17/6/2026 | The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication. | |
| Modificada | Crítica (9.8) | 1.4% | — | AsuswrtAsuswrt-merlin NEW GENAsus XT8 FirmwareAsus Tuf-ax3000 V2 Firmware+15 | 5/8/2022 | 17/6/2026 | A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 19% | — | Totolink Ex300 V2 Firmware | 7/7/2022 | 17/6/2026 | TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet. | |
| Modificada | Crítica (9) | 0.98% | — | Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+89 | 5/7/2022 | 17/6/2026 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. | |
| Modificada | Alta (7.5) | 0.96% | — | Totolink Ex300 V2 Firmware | 31/3/2022 | 17/6/2026 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check. | |
| Modificada | Media (6.5) | 0.55% | — | Totolink Ex300 V2 FirmwareTotolink A720r Firmware | 31/3/2022 | 17/6/2026 | totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption. | |
| Modificada | Media (6.1) | 0.64% | — | Totolink Ex300 V2 Firmware | 31/3/2022 | 17/6/2026 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp. | |
| Modificada | Alta (8.8) | 4.4% | — | Totolink Ex300 V2 FirmwareTotolink Ex1200t Firmware | 30/3/2022 | 17/6/2026 | totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism. |