Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.17% | — | Cisco Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a logic error in the processing of IPv6 RA packets that are received from wireless… | |
| Aplazada | Media (4.3) | 0.12% | — | Cisco Wireless Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action… | |
| Aplazada | Media (5.9) | 0.25% | — | Cisco Access Point SoftwareAI | 27/3/2024 | 17/6/2026 | A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected device. This vulnerability exists because unnecessary commands are available… | |
| Modificada | Media (6.7) | 0.24% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator… | |
| Modificada | Media (5.5) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Aironet Access Point Software | 15/4/2022 | 17/6/2026 | A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition. The device may experience a performance degradation in… | |
| Modificada | Alta (7.4) | 0.36% | — | Cisco Aironet Access Point Software | 23/9/2021 | 17/6/2026 | A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect error handling when an… | |
| Modificada | Media (4.4) | 0.23% | — | Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software | 24/3/2021 | 17/6/2026 | A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability… | |
| Modificada | Media (6.7) | 0.27% | — | Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software | 24/3/2021 | 17/6/2026 | A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that manages system startup processes. An attacker could exploit this vulnerability… | |
| Modificada | Alta (7.4) | 0.39% | — | Cisco Aironet Access Point SoftwareCisco Catalyst 9800 Firmware | 24/3/2021 | 17/6/2026 | A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of incoming mDNS traffic. An… | |
| Modificada | Alta (7.5) | 1.5% | — | Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software | 24/3/2021 | 17/6/2026 | A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker… | |
| Modificada | Alta (8.6) | 1.4% | — | Cisco Wireless LAN ControllerCisco Wireless LAN Controller SoftwareCisco Business Access PointsCisco Access Points+1 | 24/9/2020 | 17/6/2026 | A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of… | |
| Modificada | Alta (8.6) | 1.4% | — | Cisco Wireless LAN ControllerCisco Business Access PointsCisco Access PointsCisco Aironet Access Point Software | 24/9/2020 | 17/6/2026 | A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication… | |
| Modificada | Alta (7.4) | 0.49% | — | Cisco Wireless LAN ControllerCisco Business Access PointsCisco Access PointsCisco Aironet Access Point Software | 24/9/2020 | 17/6/2026 | A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by… | |
| Modificada | Media (4.1) | 0.46% | — | Cisco Aironet Access Point Software | 2/5/2018 | 17/6/2026 | A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 1850, 2800, and 3800 Series APs could allow an authenticated, adjacent attacker to bypass a configured FlexConnect access control list (ACL). The vulnerability is due to the AP… | |
| Modificada | Media (4.3) | 0.58% | — | Cisco Aironet Access Point Software | 2/5/2018 | 17/6/2026 | A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Qualcomm Atheros (QCA) based hardware platforms could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. A successful exploit could prevent… | |
| Modificada | Media (4.7) | 0.93% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point Software | 2/5/2018 | 17/6/2026 | A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerability is due to incorrect implementation of authentication… | |
| Modificada | Alta (8.6) | 3.8% | — | Cisco Aironet Access Point Software | 2/5/2018 | 17/6/2026 | A vulnerability in the implementation of Point-to-Point Tunneling Protocol (PPTP) functionality in Cisco Aironet 1810, 1830, and 1850 Series Access Points could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to… | |
| Modificada | Crítica (9.8) | 5.3% | — | Cisco Aironet Access Point Software | 15/3/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerability is due to improper implementation of authentication for accessing certain web… | |
| Modificada | Media (4.3) | 0.54% | — | Cisco Aironet Access Point Software | 26/1/2017 | 17/6/2026 | A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. Affected Products: This vulnerability affects Cisco Mobility Express 2800 Series and… | |
| Modificada | Media (4.3) | 0.45% | — | Cisco Aironet Access Point Software | 26/1/2017 | 17/6/2026 | A Denial of Service Vulnerability in 802.11 ingress packet processing of the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause the connection table to be full of invalid connections and be unable to process new incoming requests. More Information:… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Aironet Access Point Software | 22/8/2016 | 17/6/2026 | The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via crafted 802.11 frames, aka Bug ID CSCva06192. | |
| Modificada | Alta (7.8) | 0.40% | — | Cisco Aironet Access Point Software | 22/8/2016 | 17/6/2026 | Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to gain privileges via crafted CLI parameters, aka Bug ID CSCuz24725. | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Aironet Access Point Software | 22/8/2016 | 17/6/2026 | The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via a crafted AMPDU header, aka Bug ID CSCuz56288. | |
| Modificada | Alta (8.1) | 0.73% | — | Cisco Aironet Access Point Software | 10/6/2016 | 17/6/2026 | Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload) via crafted ARP packets, aka Bug ID CSCuy55803. |