Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)4.4%—Wavlink Wl-wn570ha1 Firmware3/5/202617/6/2026
A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. The affected element is the function ping_ddns of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument DDNS results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. Once again…
AnalizadaBaja (2.1)4.4%—Wavlink Wl-wn570ha1 Firmware3/5/202617/6/2026
A security vulnerability has been detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. Impacted is the function set_sys_cmd of the file /cgi-bin/adm.cgi. Such manipulation of the argument command leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may…
AnalizadaBaja (2.1)6.0%—Wavlink Wl-wn570ha1 Firmware3/5/202617/6/2026
A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation of the argument Username causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and…
AnalizadaCrítica (9.8)3.8%—Iptime N104s-r1 FirmwareIptime N104v FirmwareIptime N1E FirmwareIptime N1plus Firmware+15920/1/202617/6/2026
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
AnalizadaCrítica (9.8)9.7%—Dlink Dir-895la1 Firmware9/1/202617/6/2026
A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP client renews an…
ModificadaCrítica (9.8)1.2%—Dlink Dir-882 A1 Firmware24/1/202417/6/2026
D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.
ModificadaAlta (7.5)0.70%—ZTE Mc801a FirmwareZTE Mc801a1 Firmware14/12/202317/6/2026
There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.
ModificadaAlta (8.8)1.8%—ZTE Mc801a FirmwareZTE Mc801a1 Firmware14/12/202317/6/2026
There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.
ModificadaMedia (6.5)0.51%—ZTE Mc801a FirmwareZTE Mc801a1 Firmware14/12/202317/6/2026
There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack.
ModificadaMedia (6.7)0.62%—Siemens 6gk6108-4am00-2ba2 FirmwareSiemens 6gk6108-4am00-2da2 FirmwareSiemens 6gk5804-0ap00-2aa2 FirmwareSiemens 6gk5812-1aa00-2aa2 Firmware+1612/12/202317/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions <…
ModificadaMedia (6.7)0.64%—Siemens 6gk6108-4am00-2ba2 FirmwareSiemens 6gk6108-4am00-2da2 FirmwareSiemens 6gk5804-0ap00-2aa2 FirmwareSiemens 6gk5812-1aa00-2aa2 Firmware+1612/12/202317/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.0), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.0),…
ModificadaMedia (6.8)0.25%—Siemens 6ed1052-1md08-0ba1 FirmwareSiemens 6ed1052-2md08-0ba1 FirmwareSiemens 6ed1052-1cc08-0ba1 FirmwareSiemens 6ed1052-2cc08-0ba1 Firmware+1212/12/202317/6/2026
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions >= V8.3), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions >= V8.3), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions >= V8.3), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions >= V8.3), LOGO! 24CE (6ED1052-1CC08-0BA1) (All…
ModificadaAlta (7.5)0.55%—Unitree A1 Firmware22/11/202317/6/2026
Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web server due to the lack of any form of authentication.
ModificadaMedia (5.9)0.57%—Unitree A1 Firmware22/11/202317/6/2026
Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream. In addition, if a MITM attack is carried out, it is possible to consume the robot's resources, which could lead to a denial-of-service (DOS)…
ModificadaMedia (6.5)0.38%—Intel Ethernet Network Adapter E810-2cqda2 FirmwareIntel Ethernet Network Adapter E810-cqda1 FirmwareIntel Ethernet Network Adapter E810-cqda1 FOR OCP FirmwareIntel Ethernet Network Adapter E810-cqda1 FOR OCP 3.0 Firmware+314/11/202317/6/2026
Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaCrítica (9.1)0.75%—Mitsubishielectric Fx3u-32mt/es FirmwareMitsubishielectric Fx3u-48mt/es FirmwareMitsubishielectric Fx3u-64mt/es FirmwareMitsubishielectric Fx3u-80mt/es Firmware+2126/11/202317/6/2026
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC iQ-R series CPU modules, MELSEC iQ-R series, MELSEC iQ-L series, MELSEC Q series, MELSEC-L series, Mitsubishi Electric CNC M800V/M80V series, Mitsubishi Electric CNC…
ModificadaAlta (7.5)2.5%—Loytec Linx-212 FirmwareLoytec Lvis-3me12-a1 FirmwareLoytec Liob-586 Firmware4/11/202317/6/2026
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.
ModificadaAlta (8.2)7.4%—Loytec Linx-212 FirmwareLoytec Lvis-3me12-a1 FirmwareLoytec Liob-586 Firmware4/11/202317/6/2026
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI.
ModificadaAlta (7.5)2.5%—Loytec Linx-212 FirmwareLoytec Lvis-3me12-a1 FirmwareLoytec Liob-586 Firmware4/11/202317/6/2026
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.
ModificadaCrítica (9.1)0.85%—Mitsubishielectric Fx3g-14 Mr/ds FirmwareMitsubishielectric Fx3g-14 Mr/es FirmwareMitsubishielectric Fx3g-14 Mt/ds FirmwareMitsubishielectric Fx3g-14 Mt/dss Firmware+18613/10/202317/6/2026
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules allows a remote unauthenticated attacker to obtain sequence programs from the product or write malicious sequence programs or improper data in the product without authentication by sending illegitimate messages.
ModificadaCrítica (9.8)3.7%—Dlink Dir-859 A1 Firmware14/9/202317/6/2026
D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.
ModificadaCrítica (9.8)1.4%—Dlink Dir-880l A1 Firmware18/8/202317/6/2026
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets.
ModificadaCrítica (9.8)1.4%—Dlink Dir-880l A1 Firmware18/8/202317/6/2026
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68.
ModificadaAlta (7.5)1.3%—Dlink Dir-880l A1 Firmware18/8/202317/6/2026
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a NULL pointer dereference in the function FUN_00010824.
ModificadaCrítica (9.1)1.3%—Mitsubishielectric Fx3u-16mr/es FirmwareMitsubishielectric Fx3u-16mt/es FirmwareMitsubishielectric Fx3u-16mt/ess FirmwareMitsubishielectric Fx3u-32mr/es Firmware+14630/6/202317/6/2026
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules allows a remote unauthenticated attacker to cancel the password/keyword setting and login to the affected products by sending specially crafted packets.