Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1191 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.62%—Tp-link Archer Nx600 FirmwareTp-link Archer Nx500 FirmwareTp-link Archer Nx210 FirmwareTp-link Archer Nx200 Firmware23/3/202617/6/2026
Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting…
AnalizadaAlta (8.5)0.62%—Tp-link Archer Nx600 FirmwareTp-link Archer Nx500 FirmwareTp-link Archer Nx210 FirmwareTp-link Archer Nx200 Firmware23/3/202617/6/2026
Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting…
AnalizadaAlta (8.6)3.0%—Tp-link Archer Nx600 FirmwareTp-link Archer Nx500 FirmwareTp-link Archer Nx210 FirmwareTp-link Archer Nx200 Firmware23/3/202617/6/2026
A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.
ModificadaAlta (7.7)0.64%—Tp-link Archer Ax53 Firmware20/3/202612/8/2026
This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution…
AnalizadaAlta (7.3)2.0%—Tp-link Archer Ax53 Firmware20/3/202617/6/2026
A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell commands, enabling authenticated attackers to inject and execute arbitrary commands. Successful…
Pendiente de análisisCrítica (9.8)2.0%—Tp-link Wdr201aAI18/3/202617/6/2026
A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi endpoint improperly sanitizes user-supplied input provided to a command-related parameter in the sysCMD functionality.
Pendiente de análisisCrítica (9.1)0.67%—Tp-link Wdr201aAI18/3/202617/6/2026
The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side web pages, including login.shtml and settings.shtml. These pages embed server-side execution directives that dynamically…
AnalizadaAlta (8.5)1.8%💥 PoCTp-link Tl-wr802n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware16/3/20261/7/2026
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in…
AnalizadaAlta (7.7)0.97%💥 PoCTp-link Omada Sg2005p-pd FirmwareTp-link Omada Sg2008 FirmwareTp-link Omada Sg2008p FirmwareTp-link Omada Sg2016p Firmware+3513/3/202617/6/2026
The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the…
AnalizadaAlta (8.5)2.7%—Tp-link Tl-mr6400 Firmware12/3/202617/6/2026
A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges may be able to execute arbitrary system…
AnalizadaAlta (8.5)1.5%—Tp-link Archer Axe75 Firmware9/3/202617/6/2026
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the router is configured with sysmode=ap. Successful exploitation results in root-level privileges and…
AnalizadaMedia (6.9)0.23%—Tp-link Omada Eap610 Firmware5/3/202617/6/2026
A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This results in temporary service unavailability until the device is rebooted. This issue affects Omada EAP610 firmware versions…
AnalizadaMedia (6.9)0.29%—Tp-link Deco Be25 Firmware2/3/202617/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authenticated adjacent attacker to read arbitrary files or cause denial of service. This issue affects Deco BE25 v1.0: through 1.1.1 Build 20250822.
AnalizadaAlta (8.5)0.31%—Tp-link Deco Be25 Firmware2/3/202617/6/2026
Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arbitrary commands via crafted configuration file, impacting confidentiality, integrity and availability of the device. This…
AnalizadaAlta (7.7)0.23%—Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+1013/2/202617/6/2026
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel.…
AnalizadaBaja (2)0.36%—Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+1013/2/202617/6/2026
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow…
AnalizadaMedia (5.3)0.30%—Tp-link Archer C60 Firmware11/2/202617/6/2026
User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via a crafted URL. An attacker could run script in the device web UI context, potentially enabling credential theft, session hijacking, or unintended actions if a privileged…
ModificadaAlta (7.2)0.41%—Tp-link Tapo C260 Firmware10/2/202617/6/2026
On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change sensitive configuration parameters without…
AnalizadaAlta (8.7)22%—Tp-link Tapo C260 Firmware10/2/202617/6/2026
On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device…
ModificadaMedia (6.9)0.30%💥 PoCTp-link Tapo C260 Firmware10/2/20264/8/2026
A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalization fails. An attacker can exploit…
AnalizadaAlta (7.5)0.20%—Tp-link Tapo H100 FirmwareTp-link Tapo P100 Firmware5/2/202617/6/2026
An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications. This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation…
ModificadaMedia (5.9)0.45%—Tp-link Archer Mr200 FirmwareTp-link Archer C20 FirmwareTp-link Tl-wr850n FirmwareTp-link Tl-wr845n Firmware5/2/202617/6/2026
The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the…
AnalizadaBaja (2.3)0.18%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+174/2/202617/6/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaMedia (6)0.27%—Tp-link Archer Axe75AI3/2/202617/6/2026
When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled. This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.
ModificadaAlta (7)0.50%—Tp-link Archer Ax53 Firmware3/2/202617/6/2026
SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain device credentials through a specially crafted man‑in‑the‑middle (MITM) attack. This could enable unauthorized access if captured credentials are reused.This issue affects Archer AX53 v1.0: through…