Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.65% | — | Gleeztech Gleez CMS | 5/7/2018 | 17/6/2026 | Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Aztech Adsl Dsl5018en (1t1r) FirmwareAztech Dsl705e FirmwareAztech Dsl705eu Firmware | 12/1/2018 | 17/6/2026 | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors involving the ROM file. | |
| Modificada | Crítica (9.8) | 42% | 💥 Exploit | Aztech Adsl Dsl5018en (1t1r) FirmwareAztech Dsl705e FirmwareAztech Dsl705eu Firmware | 12/1/2018 | 17/6/2026 | Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Aztech Adsl Dsl5018en (1t1r) FirmwareAztech Dsl705e FirmwareAztech Dsl705eu Firmware | 12/1/2018 | 17/6/2026 | cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct request. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | ZTE Zxdsl 831cii Firmware | 1/12/2017 | 17/6/2026 | connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request. | |
| Modificada | Alta (7.5) | 2.1% | — | ZTE Zxdt22 Sf01 Firmware | 19/10/2017 | 17/6/2026 | All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name after host address. | |
| Modificada | Crítica (9.8) | 4.1% | — | ZTE Nr8120 FirmwareZTE Nr8120a FirmwareZTE Nr8150 FirmwareZTE Nr8250 Firmware+2 | 28/9/2017 | 17/6/2026 | All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization… | |
| Modificada | Alta (7.5) | 1.3% | — | ZTE Zxr10 1800-2s FirmwareZTE Zxr10 2800-4 FirmwareZTE Zxr10 3800-8 FirmwareZTE Zxr10 160 Firmware | 19/9/2017 | 17/6/2026 | The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration. | |
| Modificada | Crítica (9.8) | 1.1% | — | ZTE Zxr10 1800-2s FirmwareZTE Zxr10 2800-4 FirmwareZTE Zxr10 3800-8 FirmwareZTE Zxr10 160 Firmware | 19/9/2017 | 17/6/2026 | The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords. | |
| Modificada | Alta (7.5) | 2.0% | — | ZTE Ox-330p FirmwareZTE Zxhn H108n FirmwareZTE W300v1.0.0s ZRD TR1 D68 FirmwareZTE Hg110 Firmware+2 | 29/8/2017 | 17/6/2026 | ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate… | |
| Modificada | Alta (8.8) | 9.5% | 💥 Exploit | ZTE Zxv10 W300 Firmware | 24/8/2017 | 17/6/2026 | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and password pairs. | |
| Modificada | Alta (8.8) | 13% | 💥 Exploit | ZTE Zxv10 W300 Firmware | 24/8/2017 | 17/6/2026 | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | ZTE Zxv10 W300 Firmware | 24/8/2017 | 17/6/2026 | ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin". | |
| Modificada | Crítica (9.8) | 5.2% | — | Greenpacket Ox350 FirmwareHuawei Bm2022 FirmwareHuawei Hes-309m FirmwareHuawei Hes-319m Firmware+10 | 20/6/2017 | 17/6/2026 | WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request. | |
| Modificada | Media (6.5) | 4.9% | 💥 Exploit | ZTE Zxhn H108n R1A FirmwareZTE Zxv10 W300 Firmware | 30/12/2015 | 17/6/2026 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248. | |
| Modificada | Media (6.1) | 2.7% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to read arbitrary files via a full pathname in the getpage parameter. | |
| Modificada | Media (4.9) | 5.5% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/webproc HTML source code, a different vulnerability than CVE-2015-8703. | |
| Modificada | Media (5) | 2.2% | — | ZTE Zxdsl | 2/12/2014 | 17/6/2026 | ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi. | |
| Modificada | Alta (10) | 3.6% | — | ZTE Zxdsl | 2/12/2014 | 17/6/2026 | ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges. | |
| Modificada | Media (6.8) | 0.90% | — | Zteusa Zxdsl 831cii | 20/11/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators for requests that disable modem lan ports via the (1) enblftp, (2) enblhttp, (3) enblsnmp, (4) enbltelnet, (5) enbltftp, (6) enblicmp, or (7) enblssh parameter to… | |
| Modificada | Media (4.3) | 1.9% | — | Zteusa Zxdsl 831 | 20/11/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ZTE ZXDSL 831 allow remote attackers to inject arbitrary web script or HTML via the (1) tr69cAcsURL, (2) tr69cAcsUser, (3) tr69cAcsPwd, (4) tr69cConnReqPwd, or (5) tr69cDebugEnable parameter to the TR-069 client page (tr69cfg.cgi); the (6) timezone parameter to… | |
| Modificada | Media (4.3) | 2.1% | — | ZTE Zxdsl 831ZTE Zxdsl 831cii | 20/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Quick Stats page (psilan.cgi) in ZTE ZXDSL 831 and 831CII allows remote attackers to inject arbitrary web script or HTML via the domainname parameter in a save action. NOTE: this issue was SPLIT from CVE-2014-9021 per ADT1 due to different affected products and codebases. |