Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.38% | — | Tp-link Archer Be230 Firmware | 3/2/2026 | 17/6/2026 | An authenticated user with high privileges may trigger a denial‑of‑service condition in TP-Link Archer BE230 v1.2 by restoring a crafted configuration file containing an excessively long parameter. Restoring such a file can cause the device to become unresponsive, requiring a reboot to restore normal operation. This… | |
| Analizada | Media (6.8) | 0.24% | — | Tp-link Archer Be230 Firmware | 3/2/2026 | 17/6/2026 | A lack of proper input validation in the HTTP processing path in TP-Link Archer BE230 v1.2 (web modules) may allow a crafted request to cause the device’s web service to become unresponsive, resulting in a denial of service condition. A network adjacent attacker with high privileges could cause the device’s web… | |
| Modificada | Alta (8.6) | 2.1% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the TP-Link Archer BE230 v1.2 and Deco BE25 v1.0. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe… | |
| Analizada | Alta (8.5) | 2.7% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration… | |
| Modificada | Alta (8.5) | 2.5% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1.2 and Archer AX73 v2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration… | |
| Modificada | Alta (8.5) | 2.8% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2 and Archer AXE75 v1.0. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity,… | |
| Analizada | Alta (8.5) | 2.7% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity,… | |
| Analizada | Alta (8.5) | 1.5% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network… | |
| Modificada | Alta (8.5) | 1.4% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 17/6/2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration… | |
| Modificada | Alta (8.5) | 1.4% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 18/9/2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity,… | |
| Modificada | Alta (8.5) | 1.4% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 18/9/2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity,… | |
| Modificada | Alta (8.5) | 1.6% | — | Tp-link Archer Be230 Firmware | 2/2/2026 | 30/9/2026 | An OS Command Injection vulnerability exists in the Surfshark VPN login functionality in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1, allowing an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting… |