Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
161 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer… | |
| Modificada | Crítica (9.8) | 1.3% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer… | |
| Modificada | Crítica (9.8) | 1.3% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer… | |
| Modificada | Crítica (9.8) | 1.3% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability leverages the name… | |
| Modificada | Crítica (9.8) | 1.3% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability leverages the… | |
| Modificada | Crítica (9.8) | 1.3% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the confsrv set_port_fwd_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.3% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the confsrv confctl_set_app_language functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.96% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root password. An attacker does not have to do anything to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 3.7% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.89% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the confers ucloud_add_node_new functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 3.7% | — | TCL Linkhub Mesh Wifi Ac1200 | 5/8/2022 | 17/6/2026 | An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9) | 0.98% | — | Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+89 | 5/7/2022 | 17/6/2026 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. | |
| Modificada | Crítica (9.8) | 3.0% | — | Arris Sbr-ac1900p FirmwareArris Sbr-ac3200p FirmwareArris Sbr-ac1200p Firmware | 15/3/2022 | 17/6/2026 | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pptp function via the pptpUserName and pptpPassword parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Modificada | Crítica (9.8) | 2.7% | — | Arris Sbr-ac1900p FirmwareArris Sbr-ac3200p FirmwareArris Sbr-ac1200p Firmware | 15/3/2022 | 17/6/2026 | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pppoe function via the pppoeUserName, pppoePassword, and pppoe_Service parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted… | |
| Modificada | Crítica (9.8) | 2.9% | — | Arris Sbr-ac1900p FirmwareArris Sbr-ac3200p FirmwareArris Sbr-ac1200p Firmware | 15/3/2022 | 17/6/2026 | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ddns function via the DdnsUserName, DdnsHostName, and DdnsPassword parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Modificada | Crítica (9.8) | 2.7% | — | Arris Sbr-ac1900p FirmwareArris Sbr-ac3200p FirmwareArris Sbr-ac1200p Firmware | 15/3/2022 | 17/6/2026 | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ntp function via the TimeZone parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Modificada | Crítica (9.8) | 2.9% | — | Arris Sbr-ac1900p FirmwareArris Sbr-ac3200p FirmwareArris Sbr-ac1200p Firmware | 15/3/2022 | 17/6/2026 | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the firewall-local log function via the EmailAddress, SmtpServerName, SmtpUsername, and SmtpPassword parameters. This vulnerability allows attackers to execute arbitrary… | |
| Modificada | Media (6.1) | 0.73% | — | Netgear Wac120 AC Firmware | 4/3/2022 | 17/6/2026 | Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking. | |
| Modificada | Alta (8.8) | 3.8% | 💥 Exploit | Multilaser Ac1200 Re018 Firmware | 14/4/2021 | 17/6/2026 | Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers. | |
| Modificada | Alta (7.5) | 1.2% | — | Tendacn Ac1200 Firmware | 28/12/2020 | 17/6/2026 | On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to download malware named elive or CNKI E-Learning. | |
| Modificada | Alta (7.2) | 1.2% | — | Tendacn Ac1200 Firmware | 28/12/2020 | 17/6/2026 | On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234. | |
| Modificada | Alta (7.1) | 0.50% | — | Netgear Wn604 FirmwareNetgear Wnap210 FirmwareNetgear Wnap320 FirmwareNetgear Wndap350 Firmware+5 | 28/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v2 3.5.20.0 and earlier, WNAP320 3.5.20.0 and earlier, WNDAP350 3.5.20.0 and earlier, WNDAP360 3.5.20.0 and earlier, WNDAP620 2.0.11 and earlier, WNDAP660 3.5.20.0 and earlier, WND930 2.0.11 and… | |
| Modificada | Crítica (9.8) | 1.2% | — | Netgear Wac505 FirmwareNetgear Wac510 FirmwareNetgear Wac120 FirmwareNetgear Wn604 Firmware+7 | 27/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WAC120 before 2.1.7, WN604 before 3.3.10, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660… | |
| Modificada | Alta (7.4) | 0.31% | — | Netgear Wac120 FirmwareNetgear Wac505 FirmwareNetgear Wac510 FirmwareNetgear Wnap320 Firmware+7 | 27/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7, WND930 before 2.1.5, and WN604 before… | |
| Modificada | Alta (7.3) | 1.0% | — | Netgear Wac120 FirmwareNetgear Wac505 FirmwareNetgear Wac510 FirmwareNetgear Wnap320 Firmware+7 | 27/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7,… |