Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.2)0.55%—HPE Networking Instant ON Access PointAI29/9/20261/10/2026
A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating…
AplazadaCrítica (9.3)0.27%—Watchguard Access PointAI28/9/202628/9/2026
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN RoutersAIElecom Access PointsAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN RoutersAIElecom Wireless LAN Access PointsAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (5.1)0.24%—Elecom Wireless LAN RouterAIElecom Wireless LAN Access PointAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaMedia (5.1)0.29%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.
AplazadaMedia (5.1)0.33%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.
AplazadaMedia (4.8)0.25%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.
AplazadaCrítica (9.3)2.3%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required.
AplazadaCrítica (9.3)0.72%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed.
AplazadaMedia (6.9)0.12%—Elecom Wireless LAN Access PointAI13/5/202617/6/2026
ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.
Pendiente de análisisMedia (6.9)0.46%—Ruckus Access PointAI26/3/202617/6/2026
Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive information including…
AplazadaAlta (7.2)0.91%—Hikvision Wireless Access PointAI30/1/202617/6/2026
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
AplazadaAlta (7.5)0.46%—HPE Networking Instant ON Access PointsAI13/1/202617/6/2026
A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conduct a…
AplazadaAlta (7.5)0.40%—HPE Instant ON Access PointsAI13/1/202617/6/2026
A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets.
AplazadaMedia (4.3)0.17%—Cisco Access Point SoftwareAI24/9/202525/9/2026
A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a logic error in the processing of IPv6 RA packets that are received from wireless…
AplazadaMedia (4.3)0.12%—Cisco Wireless Access Point SoftwareAI24/9/202525/9/2026
A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action…
AplazadaCrítica (9.8)0.88%—Sophos AP6 Series Wireless Access PointAI9/9/202517/6/2026
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7).
AplazadaCrítica (9.8)1.1%—HPE Networking Instant ON Access PointsAI8/7/202517/6/2026
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.
AplazadaAlta (7.2)1.5%—HPE Networking Instant ON Access PointsAI8/7/202517/6/2026
An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user.
AplazadaAlta (7.2)1.4%—Hikvision Wireless Access PointAI13/6/202517/6/2026
Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
AplazadaCrítica (9.8)1.4%—Aruba Access PointAI25/9/202417/6/2026
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute…
AplazadaMedia (5.3)0.21%—UI Unifi U6 Access PointAI22/7/202417/6/2026
A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point. Affected Products: UniFi U6+ Access Point (Version 6.6.65 and earlier) Mitigation: Update your UniFi U6+ Access Point to Version 6.6.74 or later.
AplazadaMedia (4.8)0.20%—UI Unifi IOS APPAIUI Unifi Access PointAI9/7/202417/6/2026
UniFi iOS app 10.15.0 introduces a misconfiguration on 2nd Generation UniFi Access Points configured as standalone (not using UniFi Network Application) that could cause the SSID name to change and/or the WiFi Password to be removed on the 5GHz Radio. This vulnerability is fixed in UniFi iOS app 10.15.2 and later.