Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.9) | 0.83% | — | Lb-link Bl-ac1900AILb-link Bl-ac2100 AZ3AILb-link Bl-ac3600AILb-link Bl-ax1800AI+2 | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/restore of the file /cgi-bin/lighttpd.cgi of the component Web Interface. The manipulation leads to improper authentication.… | |
| Aplazada | Media (5.5) | 0.38% | — | Lb-link Bl-ac1900AILb-link Bl-ac2100 AZ3AILb-link Bl-ac3600AILb-link Bl-ax1800AI+2 | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This issue affects the function bs_GetManPwd in the library libblinkapi.so of the file /cgi-bin/lighttpd.cgi. The manipulation leads to information… | |
| Aplazada | Media (5.5) | 0.38% | — | Lb-link Bl-ac1900AILb-link Bl-ac2100 AZ3AILb-link Bl-ac3600AILb-link Bl-ax1800AI+2 | 14/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This vulnerability affects the function bs_GetHostInfo in the library libblinkapi.so of the file /cgi-bin/lighttpd.cgi. The manipulation leads to information disclosure.… | |
| Analizada | Media (5.5) | 0.70% | — | Lb-link Bl-ac3600 Firmware | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi-bin/lighttpd.cgi of the component Web Management Interface. The manipulation of the argument Password leads to information disclosure. It is possible to initiate the… | |
| Analizada | Alta (7.1) | 0.25% | — | Lb-link Bl-ac3600 Firmware | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality of the file /etc/shadow. The manipulation with the input root:blinkadmin leads to hard-coded credentials. Local access is required to approach this attack. The exploit has… | |
| Aplazada | Media (5.3) | 20% | — | Lb-link Bl-ac3600AI | 29/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_uci_set_option_string_0 of the file /cgi-bin/lighttpd.cgi of the component Password Handler. The manipulation of the argument routepwd leads to command injection. It is possible to initiate the… |