Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.74% | — | Tp-link Ac1750 Firmware | 28/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 1.1.4 Build 20211022 rel.59103(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko module. The issue results from the lack of… | |
| Modificada | Alta (8.8) | 0.74% | — | Tp-link Ac1750 Firmware | 28/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 211210 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko kernel module. The issue results from the lack of proper… | |
| Modificada | Crítica (9) | 0.98% | — | Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+89 | 5/7/2022 | 17/6/2026 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. | |
| Modificada | Alta (8.8) | 1.8% | — | Tp-link Ac1750 Firmware | 18/2/2022 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 1.1.4 Build 20211022 rel.59103(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko module. The issue results from… | |
| Modificada | Alta (8) | 6.6% | — | Tp-link Ac1750 Firmware | 14/4/2021 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of MAC addresses by the tdpServer endpoint. A crafted TCP… | |
| Modificada | Crítica (9.8) | 75% | — | Tp-link Ac1750 Firmware | 8/11/2020 | 17/6/2026 | tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled. | |
| Modificada | Crítica (9.8) | 2.2% | — | Tp-link Ac1750 Firmware | 25/3/2020 | 17/6/2026 | This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SSH port forwarding requests during initial setup. The… | |
| Modificada | Crítica (9.8) | 3.7% | — | Tp-link Ac1750 Firmware | 25/3/2020 | 17/6/2026 | This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of IPv6 connections. The issue results from the lack of proper filtering of IPv6 SSH… | |
| Modificada | Crítica (9.8) | 5.0% | — | Tp-link Ac1750 Firmware | 25/3/2020 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tmpServer service, which listens on TCP port 20002. The issue… | |
| Modificada | Crítica (9.8) | 6.5% | — | Tp-link Ac1750 Firmware | 25/3/2020 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. The issue results from the lack of proper… | |
| Modificada | Alta (8.8) | 22% | — | Tp-link Ac1750 Firmware | 25/3/2020 | 17/6/2026 | This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by… | |
| Modificada | Alta (7.8) | 5.3% | — | Tp-link Ac1750 Firmware | 25/3/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (8.8) | 41% | — | Tp-link Ac1750 Firmware | 25/3/2020 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by… | |
| Modificada | Crítica (9.8) | 9.3% | — | Tp-link Ac1750 Firmware | 25/3/2020 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an… | |
| Modificada | Crítica (9.8) | 4.2% | — | Asus Rt-ac51u FirmwareAsus Rt-ac58u FirmwareAsus Rt-ac66u FirmwareAsus Rt-ac1750 Firmware+9 | 20/4/2018 | 17/6/2026 | ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3.0.0.4.382.50276; RT-AC86U and RT-AC2900 routers with firmware… | |
| Modificada | Media (6.8) | 0.66% | — | Iodata Hdl-xr FirmwareIodata Hdl-xrw FirmwareIodata Hdl-xr2u FirmwareIodata Hdl-xr2uw Firmware+41 | 8/2/2018 | 17/6/2026 | Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Media (6.5) | 1.0% | — | Asus Rt-ac1750 Firmware | 10/5/2017 | 17/6/2026 | ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml. | |
| Modificada | Media (6.5) | 0.86% | — | Asus Rt-ac1750 Firmware | 10/5/2017 | 17/6/2026 | ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID. | |
| Modificada | Alta (7.5) | 1.2% | — | Asus Rt-ac1750 Firmware | 10/5/2017 | 17/6/2026 | ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map. | |
| Modificada | Alta (8.8) | 0.48% | — | Asus Rt-ac1750 Firmware | 10/5/2017 | 17/6/2026 | ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF. |