Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Br-6428nsAI | 23/5/2026 | 23/7/2026 | A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. The manipulation of the argument repeaterSSID leads to command injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Br-6428nsAI | 23/5/2026 | 23/7/2026 | A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM of the component POST Request Handler. Executing a manipulation of the argument… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Br-6428nsAI | 23/5/2026 | 23/7/2026 | A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. Performing a manipulation of the argument vapurl results in buffer overflow. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Br-6428nsAI | 23/5/2026 | 23/7/2026 | A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Br-6428nsAI | 18/5/2026 | 17/6/2026 | A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. Performing a manipulation of the argument stadrv_ssid results in command injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Br-6428nsAI | 18/5/2026 | 17/6/2026 | A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulation of the argument pptpUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Br-6428nsAI | 18/5/2026 | 17/6/2026 | A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. This manipulation of the argument L2TPUserName causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may… | |
| Aplazada | Alta (8.8) | 2.2% | — | Edimax Br-6428nsAI | 11/5/2026 | 5/7/2026 | EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient input validation, the attacker is able to execute arbitrary system commands on the device. | |
| Modificada | Crítica (9.8) | 8.2% | — | Edimax Br-6428ns Firmware | 15/5/2023 | 17/6/2026 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations. | |
| Modificada | Crítica (9.8) | 25% | — | Edimax Br-6428ns Firmware | 12/5/2023 | 17/6/2026 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations. | |
| Modificada | Crítica (9.8) | 8.1% | — | Edimax Br-6428ns Firmware | 12/5/2023 | 17/6/2026 | A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without any limitations. | |
| Modificada | Alta (8.8) | 29% | — | Edimax Br-6428ns Firmware | 7/2/2023 | 17/6/2026 | Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function. |