Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)1.2%—Tenda Ac500 Firmware14/7/202517/6/2026
A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. Affected by this vulnerability is the function formSetAPCfg of the file /goform/setWtpData. The manipulation of the argument radio_2g_1 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has…
AnalizadaAlta (8.8)0.54%—Zyxel Nwa50ax FirmwareZyxel Nwa50ax PRO FirmwareZyxel Nwa55axe FirmwareZyxel Nwa90ax Firmware+1914/1/202517/6/2026
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them…
AnalizadaAlta (7.1)0.80%—Tenda Ac15 FirmwareTenda AC7 FirmwareTenda Ac10u FirmwareTenda Ac500 Firmware+623/10/202417/6/2026
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may…
AnalizadaCrítica (9.8)11%—Zyxel Nwa110ax FirmwareZyxel Nwa1123-ac PRO FirmwareZyxel Nwa1123acv3 FirmwareZyxel Nwa130be Firmware+253/9/202417/6/2026
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE…
AnalizadaMedia (6.5)0.32%—Zyxel Nwa50ax FirmwareZyxel Nwa50ax-pro FirmwareZyxel Nwa55axe FirmwareZyxel Nwa90ax Firmware+1623/7/202417/6/2026
The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.
AnalizadaMedia (5.9)0.58%—Tenda Ac500 Firmware17/4/202417/6/2026
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function.
AnalizadaCrítica (9.8)0.78%—Tenda Ac500 Firmware17/4/202417/6/2026
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.
AnalizadaMedia (6.5)0.40%—Tenda Ac500 Firmware17/4/202417/6/2026
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.
AnalizadaBaja (3.8)1.0%—Tenda Ac500 Firmware17/4/202417/6/2026
Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
AnalizadaAlta (7.5)0.81%—Tenda Ac500 Firmware17/4/202417/6/2026
A Buffer Overflow vulnerability in Tenda AC500 v.2.0.1.9 allows a remote attacker to cause a denial of service via the port parameter at the goform/setVlanInfo component.
AnalizadaAlta (8.8)1.7%—Tenda Ac500 Firmware17/4/202417/6/2026
A vulnerability, which was classified as critical, has been found in Tenda AC500 2.0.1.9(1307). Affected by this issue is the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has…
AnalizadaCrítica (9.8)1.7%—Tenda Ac500 Firmware17/4/202417/6/2026
A vulnerability classified as critical was found in Tenda AC500 2.0.1.9(1307). Affected by this vulnerability is the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…
AnalizadaCrítica (9.8)8.7%—Tenda Ac500 Firmware17/4/202417/6/2026
A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
AnalizadaCrítica (9.8)1.9%—Tenda Ac500 Firmware17/4/202417/6/2026
A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been rated as critical. This issue affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the…
AnalizadaAlta (8.8)1.7%—Tenda Ac500 Firmware17/4/202417/6/2026
A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has…
AnalizadaAlta (8.8)1.8%—Tenda Ac500 Firmware17/4/202417/6/2026
A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been classified as critical. This affects the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has…
AnalizadaAlta (7.2)1.3%—Zyxel Atp100 FirmwareZyxel Atp100w FirmwareZyxel Atp200 FirmwareZyxel Atp500 Firmware+3820/2/202417/6/2026
A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware…
ModificadaMedia (5.5)0.21%—Zyxel ZLDZyxel Nwa110ax FirmwareZyxel Nwa1123acv3 FirmwareZyxel Nwa210ax Firmware+1628/11/202317/6/2026
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series…
ModificadaMedia (5.5)0.22%—Zyxel ZLDZyxel Nwa110ax FirmwareZyxel Nwa1123acv3 FirmwareZyxel Nwa210ax Firmware+1628/11/202317/6/2026
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series…
ModificadaMedia (6.5)0.77%—Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+4724/4/202317/6/2026
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions…
ModificadaAlta (7.5)11%—Tenda Ac500 Firmware27/2/202317/6/2026
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function formOneSsidCfgSet via parameter ssid.
ModificadaCrítica (9.8)17%—Tenda Ac500 Firmware27/2/202317/6/2026
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.
ModificadaCrítica (9.8)0.97%—Tenda Ac500 Firmware27/2/202317/6/2026
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.
ModificadaAlta (7.8)4.8%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+6124/5/202217/6/2026
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00…
ModificadaAlta (7.8)6.2%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+6124/5/202217/6/2026
Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions…