Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.73% | — | Sagaradio Saga1-l8b Firmware | 24/10/2018 | 17/6/2026 | SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair the device without human interaction. | |
| Modificada | Crítica (9.1) | 1.6% | — | Sagaradio Saga1-l8b Firmware | 24/10/2018 | 17/6/2026 | SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery. | |
| Modificada | Crítica (9.8) | 4.3% | — | Lutron Stanza FirmwareLutron Radiora 2 FirmwareLutron Homeworks QS Firmware | 2/6/2018 | 17/6/2026 | Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the… | |
| Modificada | Crítica (9.8) | 4.3% | — | Lutron Stanza FirmwareLutron Radiora 2 FirmwareLutron Homeworks QS Firmware | 2/6/2018 | 17/6/2026 | Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because… | |
| Modificada | Crítica (9.8) | 4.3% | — | Lutron Stanza FirmwareLutron Radiora 2 FirmwareLutron Homeworks QS Firmware | 2/6/2018 | 17/6/2026 | Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a… | |
| Modificada | Media (6.5) | 0.79% | — | Radiothermostat Ct50 FirmwareRadiothermostat Ct80 Firmware | 20/5/2018 | 17/6/2026 | The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can result in remote device temperature control, as demonstrated by a tstat t_heat request that accesses a device purchased in the Spring of 2018, and sets a home's target… | |
| Modificada | Alta (7.5) | 0.82% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsanitized GET parameter to download files from the device as the root user. The attacker can download any file from the device's filesystem. This can be used to view… | |
| Modificada | Alta (8.8) | 1.3% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests available that are not displayed on the webpage; these are only accessible by crafting a POST request with a program like cURL. There is… | |
| Modificada | Alta (7.5) | 1.2% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An information-leakage issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. There is a page in the web interface that will show you the device's serial number, regardless of whether or not you have logged in. This information-leakage issue is relevant because there is… | |
| Modificada | Alta (8.8) | 1.3% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in, there is a page that allows you to ping other hosts from the device and view the results. The user is allowed to specify which host to ping, but this variable is not… | |
| Modificada | Alta (7.5) | 1.1% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa Backhaul Radios before 2.2.3, and Mimosa Access Points before 2.2.3. These devices run Mosquitto, a lightweight message broker, to send information between devices. By using the vendor's hard-coded credentials to connect to the… | |
| Modificada | Alta (7.5) | 2.6% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. By connecting to the Mosquitto broker on an access point and one of its clients, an attacker can gather enough information to craft a command that reboots the client remotely when sent to the client's Mosquitto… | |
| Modificada | Media (5.9) | 0.66% | — | Radiojavan Radio Javan | 15/5/2017 | 17/6/2026 | The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dragonwavex Horizon Wireless Radio Firmware | 6/4/2017 | 17/6/2026 | DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions… | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc House365 Radio | 21/10/2014 | 17/6/2026 | The House365 Radio (aka com.nobexinc.wls_27853803.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc Jazz Lovers Radio | 21/10/2014 | 17/6/2026 | The Jazz Lovers Radio (aka com.nobexinc.wls_99273254.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Radiohead FAN Project Radiohead FAN | 21/10/2014 | 17/6/2026 | The Radiohead fan (aka nl.jborsje.android.bandnews.radiohead) application 4.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Radio DE LA Cato Project Radio DE LA Cato | 21/10/2014 | 17/6/2026 | The Radio de la Cato (aka com.radio.de.la.cato) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.29% | — | Nestler Ultimate Christian Radios | 21/10/2014 | 17/6/2026 | The Ultimate Christian Radios (aka com.ngg.ultimatechristianradios) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Herpin Time Radio Project Herpin Time Radio | 21/10/2014 | 17/6/2026 | The Herpin Time Radio (aka com.herpin.time.radio) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc Joint Radio Blues | 21/10/2014 | 17/6/2026 | The Joint Radio Blues (aka com.nobexinc.wls_69685189.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Islamicode Radio Bethlehem Rb2000 | 20/10/2014 | 17/6/2026 | The Radio Bethlehem RB2000 (aka com.Abuhadbah.rbl2000v2) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc Talk Radio Europe | 19/10/2014 | 17/6/2026 | The Talk Radio Europe (aka com.nobexinc.wls_31251464.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Kazakhstan Radio Project Kazakhstan Radio | 16/10/2014 | 17/6/2026 | The Kazakhstan Radio (aka com.wordbox.kazakhstanRadio) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Nobexrc Abram Radio Groove! | 4/10/2014 | 17/6/2026 | The Abram Radio Groove! (aka com.nobexinc.wls_79226887.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |