Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.2% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A directory traversal vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary file deletion. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 2.3% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to FsTFtp file overwrite. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 2.4% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary file overwrite FsTFtp file disclosure. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.9) | 30% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 3.0% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution in the vulnerable portion of the branch (deletefile). An attacker can make an authenticated HTTP… | |
| Modificada | Crítica (9.1) | 3.0% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution in the vulnerable portion of the branch (deletedir). An attacker can make an authenticated HTTP request… | |
| Modificada | Crítica (9.9) | 2.8% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 3.9% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 3.0% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Media (4.3) | 1.9% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to information disclosure. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 2.4% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 5.3% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.9) | 6.1% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 6.1% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.9) | 36% | 💥 Exploit | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 2.4% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.7% | — | Lantronix Premierwave 2050 | 22/12/2021 | 17/6/2026 | A directory traversal vulnerability exists in the Web Manager File Upload functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary file overwrite. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Media (4.9) | 1.2% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file inclusion. An attacker can make a series of authenticated HTTP requests to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 2.7% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenticated HTTP requests to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 2.7% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 2.9% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 2.9% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.1) | 2.9% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.9) | 6.1% | — | Lantronix Premierwave 2050 Firmware | 22/12/2021 | 17/6/2026 | An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 3.2% | 💥 PoC | Owasp ModsecurityTrustwave ModsecurityF5 Nginx Modsecurity WAFDebian Linux+2 | 7/12/2021 | 17/6/2026 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for… |