Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

34 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)8.4%—Wavlink Wl-wn579a3 Firmware16/2/202617/6/2026
A weakness has been identified in Wavlink WL-WN579A3 up to 20210219. This affects the function AddMac of the file /cgi-bin/wireless.cgi. This manipulation of the argument macAddr causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be…
AnalizadaMedia (5.3)8.7%—Wavlink Wl-wn579a3 Firmware16/2/202617/6/2026
A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this…
AnalizadaBaja (2.1)8.4%—Wavlink Wl-wn579a3 Firmware16/2/202617/6/2026
A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly…
AnalizadaBaja (2.1)8.7%—Wavlink Wl-wn579a3 Firmware16/2/202617/6/2026
A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a manipulation of the argument key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor…
AnalizadaBaja (2.1)8.4%—Wavlink Wl-wn579a3 Firmware16/2/202617/6/2026
A vulnerability was found in Wavlink WL-WN579A3 up to 20210219. This impacts the function multi_ssid of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument SSID2G2 results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor…
AnalizadaCrítica (9.8)3.8%—Iptime N104s-r1 FirmwareIptime N104v FirmwareIptime N1E FirmwareIptime N1plus Firmware+15920/1/202617/6/2026
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.
AnalizadaCrítica (9.8)11%—B-link Bl-wr9000 FirmwareB-link Bl-ac1900 FirmwareB-link Bl-ac2100 AZ3 FirmwareB-link Bl-x10 AC8 Firmware+513/6/202517/6/2026
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the cmd parameter in the bs_SetCmd function.
AnalizadaCrítica (9.8)1.9%—B-link Bl-wr9000 FirmwareB-link Bl-ac2100 AZ3 FirmwareB-link Bl-lte300 FirmwareB-link Bl-f1200 AT1 Firmware+313/6/202517/6/2026
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bs_SetDNSInfo function.
AnalizadaCrítica (9.8)1.6%—B-link Bl-x10 AC8 FirmwareB-link Bl-lte300 FirmwareB-link Bl-wr9000 FirmwareB-link Bl-ac2100 AZ3 Firmware+413/6/202517/6/2026
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 werediscovered to contain a command injection vulnerability via the mac parameter in the bs_SetMacBlack function.
AnalizadaCrítica (9.8)6.9%—B-link Bl-wr9000 FirmwareB-link Bl-ac2100 AZ3 FirmwareB-link Bl-x10 AC8 FirmwareB-link Bl-lte300 Firmware+413/6/202517/6/2026
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain a command injection vulnerability via the bs_SetSSIDHide function.
AnalizadaCrítica (9.8)1.6%—B-link Bl-wr9000 FirmwareB-link Bl-ac1900 FirmwareB-link Bl-ac2100 AZ3 FirmwareB-link Bl-x10 AC8 Firmware+513/6/202517/6/2026
Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT1 V1.0.0, BL-X26_AC8 V1.2.8, BLAC450M_AE4 V4.0.0 and BL-X26_DA3 V1.2.7 were discovered to contain a command injection vulnerability via the routepwd parameter in the sub_45B238 function.
AnalizadaCrítica (9.8)1.8%—Wavlink Wl-wn579a3 Firmware20/5/202517/6/2026
A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.
AnalizadaCrítica (9.8)1.8%—Wavlink Wl-wn579a3 Firmware20/5/202517/6/2026
A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.
AnalizadaCrítica (9.8)1.8%—Wavlink Wl-wn579a3 Firmware20/5/202517/6/2026
A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.
AnalizadaCrítica (9.8)32%—Dlink Dir-859 A3 Firmware18/2/202517/6/2026
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.
AnalizadaMedia (5.1)3.9%—Wavlink Wl-wn575a3 Firmware11/2/202517/6/2026
Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote devices or execute arbitrary commands without any authorization verification.
ModificadaCrítica (9.8)1.6%—Wavlink Wl-wn575a3 Firmware15/8/202317/6/2026
An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.
ModificadaAlta (7.5)0.62%—Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+113/12/202217/6/2026
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The affected products…
ModificadaMedia (5.3)0.69%—Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+113/12/202217/6/2026
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an…
ModificadaCrítica (9.8)1.0%—Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+113/12/202217/6/2026
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of…
ModificadaAlta (7.5)0.68%—Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+113/12/202217/6/2026
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). Specially crafted…
ModificadaMedia (5.5)0.23%—Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+113/12/202217/6/2026
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). Specially crafted…
ModificadaMedia (6.1)0.46%—Siemens 6gk5204-0ba00-2mb2 FirmwareSiemens 6gk5204-0ba00-2kb2 FirmwareSiemens 6gk5204-0bs00-2na3 FirmwareSiemens 6gk5204-0bs00-3la3 Firmware+113/12/202217/6/2026
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The integrated web…
ModificadaCrítica (9.8)2.8%—Wavlink Wl-wn575a3 Firmware30/8/202217/6/2026
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.
ModificadaCrítica (9.8)3.3%—Wavlink Wl-wn575a3 Firmware7/7/202217/6/2026
Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows attackers to execute arbitrary commands via a crafted POST request.