Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 2.0% | — | Edimax Br-6478acAI | 21/6/2026 | 22/6/2026 | A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulation of the argument command results in command injection. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 2.0% | — | Edimax Br-6478acAI | 21/6/2026 | 22/6/2026 | A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler. Such manipulation of the argument newpass leads to command injection. The attack can be launched remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 2.0% | — | Edimax Br-6478acAI | 21/6/2026 | 22/6/2026 | A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation of the argument interface causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Baja (2.1) | 2.0% | — | Edimax Br-6478acAI | 21/6/2026 | 22/6/2026 | A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/pptpUserName/L2TPUserName results in command injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Br-6478acAI | 21/6/2026 | 23/6/2026 | A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. It is possible to initiate the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 1.1% | — | Edimax Br-6478acAI | 31/5/2026 | 22/7/2026 | A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.47% | — | Edimax Br-6478acAI | 31/5/2026 | 22/7/2026 | A vulnerability was identified in Edimax BR-6478AC 1.23. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack may be performed from remote. The… | |
| Aplazada | Alta (7.4) | 0.46% | — | Edimax Br-6478acAI | 31/5/2026 | 22/7/2026 | A vulnerability was found in Edimax BR-6478AC 1.23. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. The manipulation of the argument ShareName/SelectName results in buffer overflow. The attack can be executed remotely. The exploit has been made public and… | |
| Aplazada | Alta (7.4) | 0.46% | — | Edimax Br-6478acAI | 31/5/2026 | 22/7/2026 | A vulnerability has been found in Edimax BR-6478AC 1.23. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. The manipulation of the argument UserName/Password leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Baja (2.1) | 1.3% | — | Edimax Br-6478acAI | 30/5/2026 | 22/7/2026 | A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack may be initiated remotely. The exploit has been made available… | |
| Aplazada | Alta (7.4) | 0.75% | — | Edimax Br-6478acAI | 30/5/2026 | 22/7/2026 | A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID results in buffer overflow. The attack can be launched remotely. The exploit has been released to the… | |
| Aplazada | Alta (7.4) | 0.45% | — | Edimax Br-6478acAI | 30/5/2026 | 22/7/2026 | A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to stack-based buffer overflow. The attack can be initiated remotely. The… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Br-6478acAI | 25/5/2026 | 23/7/2026 | A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. The manipulation of the argument L2TPUserName leads to buffer overflow. The attack may be initiated remotely. The exploit… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Br-6478acAI | 25/5/2026 | 23/7/2026 | A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. Executing a manipulation of the argument selSSID can lead to buffer overflow. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Br-6478acAI | 25/5/2026 | 23/7/2026 | A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated remotely. The exploit… | |
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Br-6478acAI | 25/5/2026 | 23/7/2026 | A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to launch the attack remotely. The exploit is… | |
| Analizada | Baja (2) | 20% | — | Edimax Br-6478ac V3 Firmware | 5/12/2025 | 17/6/2026 | A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm/formSysCmd. This manipulation of the argument sysCmd causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early… | |
| Analizada | Baja (2) | 20% | — | Edimax Br-6478ac V3 Firmware | 5/12/2025 | 17/6/2026 | A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/formTracerouteDiagnosticRun. The manipulation of the argument host results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was… | |
| Analizada | Baja (2) | 17% | — | Edimax Br-6478ac V3 Firmware | 5/12/2025 | 17/6/2026 | A security vulnerability has been detected in Edimax BR-6478AC V3 1.0.15. This issue affects the function sub_416898 of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be… | |
| Analizada | Media (6.5) | 9.8% | — | Edimax Br-6478ac V3 Firmware | 15/4/2025 | 17/6/2026 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat. | |
| Analizada | Media (6.5) | 5.1% | — | Edimax Br-6478ac V3 Firmware | 15/4/2025 | 17/6/2026 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin parameter in the formWsc function. | |
| Analizada | Media (6.5) | 9.5% | — | Edimax Br-6478ac V3 Firmware | 15/4/2025 | 17/6/2026 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup. | |
| Analizada | Media (6.5) | 9.8% | — | Edimax Br-6478ac V3 Firmware | 15/4/2025 | 17/6/2026 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare. | |
| Analizada | Crítica (9.8) | 11% | — | Edimax Br-6478ac V3 Firmware | 4/4/2025 | 17/6/2026 | Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel | |
| Modificada | Crítica (9.8) | 0.57% | — | Edimax Br-6478ac Firmware | 16/1/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function. |