Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

43 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)9.4%—Adslr B-qe2w401 Firmware1/12/20253/9/2026
A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor…
AnalizadaBaja (2.1)9.4%—Adslr B-qe2w401 Firmware1/12/20253/9/2026
A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.cgi. The manipulation of the argument mac leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…
AnalizadaBaja (2.1)7.1%—Adslr B-qe2w401 Firmware1/12/202517/6/2026
A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulation of the argument mac can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted…
AnalizadaBaja (2.1)7.1%—Adslr B-qe2w401 Firmware1/12/20253/9/2026
A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cgi. Performing manipulation of the argument del_swifimac results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may…
AplazadaMedia (6.3)0.31%—Radicaldesigns RadslideAI3/3/202517/6/2026
Missing Authorization vulnerability in radicaldesigns radSLIDE radslide allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects radSLIDE: from n/a through <= 2.1.
AnalizadaCrítica (9.8)3.2%—Adslr Vw2100 Firmware14/6/202317/6/2026
There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.
ModificadaMedia (5.1)0.72%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.
ModificadaMedia (5.2)0.27%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.
ModificadaAlta (7.1)0.24%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system.
ModificadaAlta (7.5)15%—UI Unifi ControllerW1.fi HostapdAsus Rt-n11Broadcom Adsl+2138/6/202017/6/2026
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
ModificadaAlta (8.8)1.2%—Realtek Adsl Router SOC Firmware8/6/202017/6/2026
A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows attackers using a default password to execute arbitrary commands remotely via the build-in network monitoring tool.
ModificadaMedia (5.4)0.59%—Tendacn Adsl Firmware23/12/201817/6/2026
Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client.
ModificadaCrítica (9.8)16%—Aztech Adsl Dsl5018en (1t1r) FirmwareAztech Dsl705e FirmwareAztech Dsl705eu Firmware12/1/201817/6/2026
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors involving the ROM file.
ModificadaCrítica (9.8)42%—Aztech Adsl Dsl5018en (1t1r) FirmwareAztech Dsl705e FirmwareAztech Dsl705eu Firmware12/1/201817/6/2026
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
ModificadaAlta (7.5)13%—Aztech Adsl Dsl5018en (1t1r) FirmwareAztech Dsl705e FirmwareAztech Dsl705eu Firmware12/1/201817/6/2026
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct request.
ModificadaCrítica (9.8)66%—Fiberhome Adsl An1020-25 Firmware7/9/201717/6/2026
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. Due to improper authentication on this page, the software accepts…
ModificadaAlta (10)2.4%—Digicom Dg-5514t Adsl Router Firmware10/12/201417/6/2026
Digicom DG-5514T ADSL router with firmware 3.2 generates predictable session IDs, which allows remote attackers to gain administrator privileges via a brute force session hijacking attack.
ModificadaAlta (7.8)11%—Acme Micro HttpdDlink Dsl2740uDlink Dsl2750uNetgear Mr-adsl-dg834+124/7/201417/6/2026
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.
ModificadaMedia (4.3)1.5%—Comtrend Ct-507it Adsl Router2/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter.
ModificadaAlta (10)2.4%—Aztech Adsl2/2+4-port Router3/4/200916/6/2026
Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers to obtain access if this default is not changed.
ModificadaAlta (10)3.7%—Aztech Adsl2/2+4-port Router30/3/200916/6/2026
cgi-bin/script in Aztech ADSL2/2+ 4-port router 3.7.0 build 070426 allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
ModificadaAlta (7.8)9.7%—TP Neostrada Livebox Adsl Router20/3/200916/6/2026
The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI.
ModificadaMedia (5)3.3%—ECI Telecom B-focus Wireless 802.11bg Adsl2+ Router4/11/200616/6/2026
ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI.
ModificadaMedia (5)1.9%—Inca Im-204 Adsl Router30/10/200616/6/2026
Directory traversal vulnerability in /cgi-bin/webcm in INCA IM-204 allows remote attackers to read arbitrary files via a "/./." (modified dot dot) sequences in the getpage parameter.
ModificadaMedia (5)6.7%—BT Voyager 2091 Wireless Adsl Router13/7/200616/6/2026
BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as configuration information via (1) /btvoyager_getconfig.sh, PPP credentials via (2) btvoyager_getpppcreds.sh, and decode…