Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

272 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.7)1.0%—Tp-link Archer Ax90AI1/10/20262/10/2026
A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot. Successful exploitation may result in complete device…
AplazadaAlta (7.1)0.45%—ArcherysecAI16/9/202624/9/2026
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses,…
AplazadaMedia (5.3)0.47%—Tp-link Archer Mr600AITp-link Tl-mr6400AI10/9/202611/9/2026
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful…
AplazadaMedia (4.8)0.73%—Tp-link Archer Mr600AITp-link Tl-mr6400AI10/9/202611/9/2026
An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a…
AplazadaMedia (6.1)0.24%—Tp-link Archer Ax55AI3/9/20268/9/2026
A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session…
AplazadaAlta (7.7)0.26%—Tp-link Archer Ax55AI3/9/20268/9/2026
A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. Successful exploitation may cause the…
AplazadaCrítica (9.8)0.89%—Gpt-researcherAI27/8/20269/9/2026
A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.
Pendiente de análisisAlta (8.5)2.3%—Tp-link Archer Be3600AI24/8/202628/8/2026
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may…
Pendiente de análisisAlta (8.7)3.1%—Tp-link Archer Be800AITp-link Archer Be3600AITp-link Archer Ax75AI24/8/202628/8/2026
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root…
Pendiente de análisisAlta (8.5)2.0%—Tp-link Archer Be800AI24/8/202628/8/2026
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection. Successful exploitation may enable persistent backdoors, credential theft, LAN…
AnalizadaAlta (7.1)0.87%—Tp-link Tl-mr100 FirmwareTp-link Archer Mr600 FirmwareTp-link Tl-mr150 FirmwareTp-link Tl-mr6400 Firmware20/8/20263/9/2026
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated…
AnalizadaAlta (8.5)2.8%—Tp-link Archer C20 Firmware19/8/20268/9/2026
An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device…
Pendiente de análisisMedia (6.8)0.20%—Tp-link Archer A6AI7/8/202618/8/2026
A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations. By sending crafted systool instructions through the asynchronous request path, successful exploitation…
AnalizadaAlta (8.5)2.5%—Tp-link Archer Axe75 Firmware31/7/20267/8/2026
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special…
AplazadaMedia (5.2)0.34%—Tp-link TL Wr845nAITp-link TL Wr850nAITp-link TL Wr902acAITp-link Archer C20AI+127/7/202611/8/2026
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis.…
Pendiente de análisisCrítica (9.8)0.89%—Open Source GPT Researcher GPT ResearcherAI15/7/202616/7/2026
An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.
AnalizadaMedia (5.1)1.4%—Tp-link Archer Vx1800v Firmware14/7/20266/8/2026
A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. An authenticated user with sufficient privileges may be able to modify account…
AnalizadaAlta (8.5)2.1%—Tp-link Archer Vx1800v Firmware14/7/20266/8/2026
An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges.…
AnalizadaAlta (8.6)0.84%—Tp-link Archer Vx1800v Firmware14/7/20266/8/2026
An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and…
AplazadaAlta (7)0.28%—Tp-link Archer C5AI2/7/20262/7/2026
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side validation and lack of proper output encoding of user-controlled input in a certain field. An attacker with administrative privileges can inject crafted…
AplazadaMedia (5.9)0.46%—Tp-link Archer Ax20 V2AI30/6/20262/7/2026
An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface. An unauthenticated attacker can craft URLs containing URL-encoded path traversal sequences. When processed by the embedded web server, these inputs may…
AplazadaAlta (8.5)2.5%—Tp-link Archer Ax12AITp-link Archer Ax17AITp-link Archer Ax18AITp-link Archer Ax1300AI10/6/202617/6/2026
An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue stems…
AplazadaAlta (8.5)2.1%—Tp-link Archer Mr600AI8/6/202623/7/2026
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when applying configuration…
AplazadaBaja (2.1)0.25%—Zilliztech Deep-searcherAI7/6/202623/7/2026
A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been…
AnalizadaAlta (8.7)0.40%—Tp-link Archer C64 Firmware28/5/202617/6/2026
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. Successful exploitation could allow an…