Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)2.5%—Tp-link Archer Axe75 Firmware31/7/20267/8/2026
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special…
AnalizadaAlta (8.5)1.4%—Tp-link Archer Axe75 Firmware9/3/202617/6/2026
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the router is configured with sysmode=ap. Successful exploitation results in root-level privileges and…
AplazadaMedia (6)0.27%—Tp-link Archer Axe75AI3/2/202617/6/2026
When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled. This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.
AnalizadaMedia (6.9)0.30%—Tp-link Archer Axe75 Firmware9/1/202617/6/2026
Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects Archer AXE75 v1.6: ≤ build 20250107.
ModificadaAlta (8.8)1.1%—Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware+111/1/202417/6/2026
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
ModificadaAlta (8)0.45%—Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Archer Axe75 Firmware11/1/202417/6/2026
Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.