Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.2% | — | Evenroute Iqrouter Firmware | 21/4/2020 | 17/6/2026 | IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a… | |
| Analizada | Crítica (9.8) | 15% | ⚠ Explotación activa | Sumavision Enhanced Multimedia Router Firmware | 11/3/2020 | 17/6/2026 | goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request. | |
| Modificada | Alta (7.5) | 0.91% | — | 360 P0 Router Firmware360 F5C Router Firmware | 4/3/2020 | 17/6/2026 | By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication. This affects 360 router P0 and F5C. | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+14 | 27/1/2020 | 17/6/2026 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through… | |
| Modificada | Alta (7.5) | 8.7% | 💥 Exploit | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+14 | 27/1/2020 | 17/6/2026 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0,… | |
| Modificada | Alta (8.8) | 2.5% | — | Cisco IOSCisco Cloud Services Router 1000v FirmwareCisco Integrated Services Virtual Router Firmware | 25/9/2019 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.8) | 1.5% | — | Cisco Rv325 Dual WAN Gigabit VPN Router FirmwareCisco Rv320 Dual Gigabit WAN VPN Router Software | 3/5/2019 | 17/6/2026 | A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. An attacker could use this impersonated session to create a new… | |
| Modificada | Crítica (9.8) | 3.7% | — | Softcase T-router Firmware | 21/9/2018 | 17/6/2026 | An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary files on the system as root, as demonstrated by code execution after writing to a crontab file. This is fixed in production builds as of Spring 2018. | |
| Modificada | Crítica (9.8) | 2.3% | — | Softcase T-router Firmware | 21/9/2018 | 17/6/2026 | An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol. If the command syntax is correct, there is code execution both on the other modem and on the main servers. This is fixed in production builds as of Spring 2018. | |
| Modificada | Media (5.9) | 0.79% | — | Kraftway 24f2xg Router Firmware | 17/8/2018 | 17/6/2026 | Usage of SSLv2 and SSLv3 leads to transmitted data decryption in Kraftway 24F2XG Router firmware 3.5.30.1118. | |
| Modificada | Alta (7.5) | 2.1% | — | Kraftway 24f2xg Router Firmware | 17/8/2018 | 17/6/2026 | A Buffer Overflow exploited through web interface by remote attacker can cause denial of service in Kraftway 24F2XG Router firmware 3.5.30.1118. | |
| Modificada | Crítica (9.8) | 7.7% | — | Kraftway 24f2xg Router Firmware | 17/8/2018 | 17/6/2026 | A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG Router firmware 3.5.30.1118. | |
| Modificada | Media (6.5) | 1.4% | — | Kraftway 24f2xg Router Firmware | 17/8/2018 | 17/6/2026 | An attacker with low privileges can cause denial of service in Kraftway 24F2XG Router firmware version 3.5.30.1118. | |
| Modificada | Media (6.5) | 2.0% | — | Kraftway 24f2xg Router Firmware | 17/8/2018 | 17/6/2026 | Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftway 24F2XG Router firmware version 3.5.30.1118. | |
| Modificada | Crítica (9.8) | 4.7% | — | Kraftway 24f2xg Router Firmware | 17/8/2018 | 17/6/2026 | Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the router. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Dasannetworks Gpon Router Firmware | 4/5/2018 | 17/6/2026 | An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands… | |
| Analizada | Crítica (9.8) | 93% | ⚠ Explotación activa💥 Exploit | Dasannetworks Gpon Router Firmware | 4/5/2018 | 17/6/2026 | An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Mikrotik Router Firmware | 16/4/2018 | 17/6/2026 | A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on port 21 that begins with many '\0' characters, preventing the affected router from accepting new FTP connections. The router will reboot after… | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Mikrotik Router Firmware | 13/12/2017 | 17/6/2026 | MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets. | |
| Modificada | Media (6.4) | 0.42% | — | Cisco Ir800 Integrated Services Router Firmware | 7/9/2017 | 17/6/2026 | A vulnerability in the ROM Monitor (ROMMON) code of Cisco IR800 Integrated Services Router Software could allow an unauthenticated, local attacker to boot an unsigned Hypervisor on an affected device and compromise the integrity of the system. The vulnerability is due to insufficient sanitization of user input. An… | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | Cisco Dpc3928ad Docsis Wireless Router Firmware | 20/7/2017 | 17/6/2026 | Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321. | |
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | Geneko Gwr352 3G Router FirmwareGeneko Gwr352wv Wide Voltage 3G Router FirmwareGeneko Gwr252 Edge Router FirmwareGeneko Gwr202 Gprs Router Firmware | 19/7/2017 | 17/6/2026 | Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file. | |
| Modificada | Alta (8.8) | 1.2% | — | Intenogroup Inteno Router Firmware | 17/7/2017 | 17/6/2026 | Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.) | |
| Modificada | Crítica (9.8) | 5.2% | — | Greenpacket Ox350 FirmwareHuawei Bm2022 FirmwareHuawei Hes-309m FirmwareHuawei Hes-319m Firmware+10 | 20/6/2017 | 17/6/2026 | WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request. | |
| Modificada | Media (6.1) | 0.95% | — | Aries Networks Qwr-1104 Wireless-n Router Firmware | 28/5/2017 | 17/6/2026 | Aries QWR-1104 Wireless-N Router with Firmware Version WRC.253.2.0913 has XSS on the Wireless Site Survey page, exploitable with the name of an access point. |