Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 0.72% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+97 | 13/12/2022 | 17/6/2026 | Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data. | |
| Modificada | Media (5.2) | 0.27% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+97 | 13/12/2022 | 17/6/2026 | Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords. | |
| Modificada | Alta (7.1) | 0.24% | — | Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+97 | 13/12/2022 | 17/6/2026 | Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system. | |
| Modificada | Alta (8.8) | 1.2% | — | Realtek Adsl Router SOC Firmware | 8/6/2020 | 17/6/2026 | A security misconfiguration vulnerability exists in the SDK of some Realtek ADSL/PON Modem SoC firmware, which allows attackers using a default password to execute arbitrary commands remotely via the build-in network monitoring tool. | |
| Modificada | Alta (10) | 2.4% | — | Digicom Dg-5514t Adsl Router Firmware | 10/12/2014 | 17/6/2026 | Digicom DG-5514T ADSL router with firmware 3.2 generates predictable session IDs, which allows remote attackers to gain administrator privileges via a brute force session hijacking attack. | |
| Modificada | Media (4.3) | 1.5% | — | Comtrend Ct-507it Adsl Router | 2/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter. | |
| Modificada | Alta (7.8) | 9.7% | — | TP Neostrada Livebox Adsl Router | 20/3/2009 | 16/6/2026 | The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI. | |
| Modificada | Media (5) | 1.9% | — | Inca Im-204 Adsl Router | 30/10/2006 | 16/6/2026 | Directory traversal vulnerability in /cgi-bin/webcm in INCA IM-204 allows remote attackers to read arbitrary files via a "/./." (modified dot dot) sequences in the getpage parameter. | |
| Modificada | Media (5) | 6.7% | — | BT Voyager 2091 Wireless Adsl Router | 13/7/2006 | 16/6/2026 | BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as configuration information via (1) /btvoyager_getconfig.sh, PPP credentials via (2) btvoyager_getpppcreds.sh, and decode… | |
| Modificada | Alta (7.5) | 1.6% | — | Arcowave Systems Wlan AP + Adsl Router | 14/5/2005 | 16/6/2026 | Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell. | |
| Modificada | Media (4.3) | 1.9% | — | Edimax Full Rate Adsl Router | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Alta (7.5) | 1.7% | — | Edimax Full Rate Adsl Router | 31/12/2004 | 16/6/2026 | The web management interface in Edimax AR-6004 ADSL Routers uses a default administrator name and password, which also appear as the default login text for the management interface, which allows remote attackers to gain access. | |
| Modificada | Media (5) | 3.1% | — | Conceptronic Cadslr1 Adsl Router | 31/12/2004 | 16/6/2026 | The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username. | |
| Modificada | Media (5) | 3.0% | — | BT Voyager 2000 Wireless Adsl Router | 6/12/2004 | 16/6/2026 | The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext. | |
| Modificada | Alta (10) | 2.3% | — | Telindus 1120 Adsl Router | 31/12/2002 | 16/6/2026 | Telindus 1100 ASDL router running firmware 6.0.x uses weak encryption for UDP session traffic, which allows remote attackers to gain unauthorized access by sniffing and decrypting the administrative password. | |
| Modificada | Alta (7.5) | 2.9% | — | Telindus Adsl Router | 4/10/2002 | 16/6/2026 | Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which generates a reply that includes the router's password and other sensitive information in cleartext. |