Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.47% | — | Tp-link Archer Mr600AITp-link Tl-mr6400AI | 10/9/2026 | 11/9/2026 | A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful… | |
| Aplazada | Media (4.8) | 0.73% | — | Tp-link Archer Mr600AITp-link Tl-mr6400AI | 10/9/2026 | 11/9/2026 | An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a… | |
| Analizada | Alta (7.1) | 0.87% | — | Tp-link Tl-mr100 FirmwareTp-link Archer Mr600 FirmwareTp-link Tl-mr150 FirmwareTp-link Tl-mr6400 Firmware | 20/8/2026 | 3/9/2026 | An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated… | |
| Aplazada | Alta (8.5) | 2.1% | — | Tp-link Archer Mr600AI | 8/6/2026 | 23/7/2026 | A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when applying configuration… | |
| Analizada | Alta (8.5) | 2.8% | — | Tp-link Archer Mr600 Firmware | 26/1/2026 | 17/6/2026 | Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise. |