Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.48%—Alcatel-lucent ALE NOEAIAlcatel-lucent ALE SIPAI7/5/202417/6/2026
An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of improper privilege management, an authenticated attacker is able to create symlinks to sensitive and protected data in locations that are used for debugging…
AplazadaAlta (7.4)0.20%—Alcatel-lucent ALE NOEAIAlcatel-lucent ALE SIPAI7/5/202417/6/2026
An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker is able to replace the verified firmware image with malicious firmware during the update…
ModificadaMedia (6.1)0.75%—Alcatelmobile Cingular Flip 2 Firmware26/11/201917/6/2026
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware…
ModificadaMedia (6.8)1.1%—Alcatelmobile Cingular Flip 2 Firmware26/11/201917/6/2026
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An attacker with physical access to the device can abuse this vulnerability to execute arbitrary OS commands as the root user via the application's UI.
ModificadaMedia (6.8)0.48%—Alcatelmobile Cingular Flip 2 Firmware26/11/201917/6/2026
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the /data/local/tmp/ directory. The System application that implements the lock screen checks for the existence of a specific file and disables PIN authentication if it exists. This file would typically…
ModificadaCrítica (9.8)2.1%—TCL Alcatel Linkzone Firmware2/8/201917/6/2026
The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password.
ModificadaMedia (6.8)0.50%—Alcatel A30 Firmware29/8/201817/6/2026
The Alcatel A30 device with a build fingerprint of TCL/5046G/MICKEY6US:7.0/NRD90M/J63:user/release-keys contains a hidden privilege escalation capability to achieve command execution as the root user. They have made modifications that allow a user with physical access to the device to obtain a root shell via ADB.…
ModificadaAlta (7.5)2.2%—Alcatel-lucent Home Device Manager9/8/201717/6/2026
Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as target devices.
ModificadaMedia (5.4)0.64%—Alcatel-lucent Motive Home Device Manager23/3/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceTypeID parameter to DeviceType/getDeviceType.do; the (2) policyActionClass or (3) policyActionName…
ModificadaCrítica (9.8)13%—Alcatel-lucent Omnivista 8770 Network Management System3/12/201617/6/2026
Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An attacker can bypass authentication, and OmniVista invokes methods (AddJobSet, AddJob, and ExecuteNow) that can be used to run arbitrary commands on the server, with the…
ModificadaMedia (6.8)0.92%—Alcatel-lucent Cellpipe 7130 RG 5ae.m2013 HOL Firmware23/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL with firmware 1.0.0.20h.HOL allows remote attackers to hijack the authentication of administrators for requests that create a user account via an add_user action in a request to password.cmd.
ModificadaMedia (4.3)1.0%—Alcatel-lucent Cellpipe 7130 Router Firmware18/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to inject arbitrary web script or HTML via the "Custom application" field in the "port triggering" menu.
ModificadaMedia (6.8)3.0%—Alcatel-lucent Omniswitch Firmware16/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01…
ModificadaMedia (4.3)2.0%—Alcatel-lucent Omniswitch Firmware16/6/201517/6/2026
The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before 6.6.4.309.R01 and 6.6.5.x before 6.6.5.80.R02 generates weak session identifiers, which allows remote attackers to hijack arbitrary sessions via a brute force attack.
ModificadaMedia (4.3)1.3%—Alcatel-lucent Omnitouch 8400 Instant Communications SuiteAlcatel-lucent Omnitouch 8460 Advanced Communication ServerAlcatel-lucent Omnitouch 8660 MY TeamworkAlcatel-lucent Omnitouch 8670 Automated Delivery Message Delivery System20/8/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant…
ModificadaAlta (7.5)1.3%—Alcatel Speedtouch 5X6 Router FirmwareAlcatel Speedtouch 5X6 Router22/11/201116/6/2026
The UPnP IGD implementation on SpeedTouch 5x6 devices with firmware before 6.2.29 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
ModificadaBaja (3.3)0.94%—Alcatel-lucent Omnivista8/3/201116/6/2026
Directory traversal vulnerability in the NMS server in Alcatel-Lucent OmniVista 4760 R5.1.06.03 and earlier allows remote attackers to read arbitrary files via directory traversal sequences in HTTP GET requests, related to the lang variable.
ModificadaMedia (5.8)2.3%—Alcatel-lucent Omnipcx8/3/201116/6/2026
Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Communication Server (CS) in Alcatel-Lucent OmniPCX Enterprise before R9.0 H1.301.50 allow remote attackers to execute arbitrary code via crafted HTTP headers.
ModificadaMedia (5.4)1.9%—Alcatel-lucent Omnivista 4760 Server23/9/201016/6/2026
Stack-based buffer overflow in the HTTP proxy service in Alcatel-Lucent OmniVista 4760 server before R5.1.06.03.c_Patch3 allows remote attackers to execute arbitrary code or cause a denial of service (service crash) via a long request.
ModificadaMedia (6.9)0.96%—Alcatel-lucent CcagentAlcatel-lucent Omnitouch Contact Center23/9/201016/6/2026
The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote…
ModificadaAlta (7.6)1.1%—Alcatel-lucent CcagentAlcatel-lucent Omnitouch Contact Center23/9/201016/6/2026
The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables maintenance access, which allows remote attackers to monitor or reconfigure Contact Center operations via vectors involving TSA_maintenance.exe.
ModificadaAlta (10)8.2%—Alcatel AOS3/10/200816/6/2026
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before 5.1.6.463.R02, 5.4 before 5.4.1.429.R01, 6.1.3 before 6.1.3.965.R01, 6.1.5 before 6.1.5.595.R01, and 6.3 before 6.3.1.966.R01 allows remote…
ModificadaAlta (10)8.8%—Alcatel-lucent Omnipcx Office2/4/200816/6/2026
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter.
ModificadaAlta (8.5)2.4%—Alcatel-lucent Omnipcx20/11/200716/6/2026
The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or…
ModificadaMedia (4.3)2.0%—Alcatel-lucent Omnivista22/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the action parameter to php-bin/Webclient.php or (2) the Langue parameter to the default URI.