Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.27%—Gl-inet Mt6000 FirmwareGl-inet Mt3000 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 Firmware+1724/10/202417/6/2026
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.
AnalizadaAlta (8.8)0.67%—Gl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 FirmwareGl-inet B3000 Firmware+1724/10/202417/6/2026
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.
AnalizadaAlta (8)0.49%—Gl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 FirmwareGl-inet B3000 Firmware+1724/10/202417/6/2026
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication…
AnalizadaAlta (8)4.1%—Gl-inet Mt6000 FirmwareGl-inet B1300 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 Firmware+1724/10/202417/6/2026
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.
AnalizadaMedia (6.5)0.23%—Gl-inet Mt3000 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 Firmware+1724/10/202417/6/2026
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.