Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.4% | — | AsuswrtAsuswrt-merlin NEW GENAsus XT8 FirmwareAsus Tuf-ax3000 V2 Firmware+15 | 5/8/2022 | 17/6/2026 | A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.4% | — | Asuswrt | 20/3/2020 | 17/6/2026 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI. | |
| Modificada | Crítica (9.8) | 3.8% | — | Asuswrt | 20/3/2020 | 17/6/2026 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell. | |
| Modificada | Alta (7.5) | 1.2% | — | Asuswrt | 20/3/2020 | 17/6/2026 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router. | |
| Modificada | Media (5.3) | 1.5% | — | Asuswrt-merlinAsus Firmware | 27/2/2020 | 17/6/2026 | Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page. | |
| Modificada | Media (5.3) | 1.5% | — | Asus FirmwareAsuswrt-merlin | 27/2/2020 | 17/6/2026 | Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page. | |
| Modificada | Alta (7.5) | 1.7% | — | Asuswrt-merlin | 17/9/2019 | 17/6/2026 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a long string over UDP, which may lead to an information leak. | |
| Modificada | Crítica (9.8) | 5.2% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+10 | 15/10/2018 | 17/6/2026 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution | |
| Modificada | Crítica (9.8) | 5.4% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+10 | 15/10/2018 | 17/6/2026 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a… | |
| Modificada | Alta (8.8) | 1.5% | — | Asuswrt | 31/1/2018 | 17/6/2026 | Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt. | |
| Modificada | Crítica (9.6) | 3.1% | — | Asuswrt | 31/1/2018 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as the newest and thus are vulnerable at this time. This vulnerability… | |
| Modificada | Alta (8.3) | 2.1% | — | Asuswrt | 31/1/2018 | 17/6/2026 | Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access. | |
| Modificada | Alta (8.8) | 2.0% | — | Asuswrt | 31/1/2018 | 17/6/2026 | Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any action knowing administrator session token by using a specific User-Agent string. | |
| Modificada | Crítica (9.8) | 85% | — | Asuswrt | 22/1/2018 | 17/6/2026 | An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently… | |
| Modificada | Crítica (9.8) | 87% | — | Asuswrt | 22/1/2018 | 17/6/2026 | An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails. | |
| Modificada | Alta (8.8) | 1.9% | — | Asuswrt-merlin | 17/1/2018 | 17/6/2026 | Stack-based buffer overflow in the ej_update_variables function in router/httpd/web.c on ASUS routers (when using software from https://github.com/RMerl/asuswrt-merlin) allows web authenticated attackers to execute code via a request that updates a setting. In ej_update_variables, the length of the variable… | |
| Modificada | Alta (8.8) | 2.7% | — | Asuswrt-merlin | 9/8/2017 | 17/6/2026 | Stack buffer overflow in httpd in Asuswrt-Merlin firmware 380.67_0RT-AC5300 and earlier for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU,… | |
| Modificada | Crítica (9.8) | 5.6% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+24 | 18/7/2017 | 17/6/2026 | Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100,… | |
| Modificada | Alta (7.8) | 1.8% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+24 | 17/7/2017 | 17/6/2026 | Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200,… | |
| Modificada | Alta (7.8) | 2.8% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+24 | 17/7/2017 | 17/6/2026 | Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200,… |