Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.7% | — | Comfast Cf-xr11 Firmware | 18/9/2025 | 17/6/2026 | A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt. The phy_interface parameter is not sanitized, allowing attackers to inject arbitrary commands via a POST request to… | |
| Analizada | Crítica (9.8) | 11% | — | Comfast Cf-xr11 Firmware | 11/9/2024 | 17/6/2026 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface. | |
| Modificada | Crítica (9.8) | 2.4% | — | Comfast Cf-xr11 Firmware | 15/8/2023 | 17/6/2026 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name. | |
| Modificada | Crítica (9.8) | 1.2% | — | Comfast Cf-xr11 Firmware | 15/8/2023 | 17/6/2026 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt. | |
| Modificada | Crítica (9.8) | 2.4% | — | Comfast Cf-xr11 Firmware | 15/8/2023 | 17/6/2026 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr. | |
| Modificada | Crítica (9.8) | 1.2% | — | Comfast Cf-xr11 Firmware | 15/8/2023 | 17/6/2026 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt. | |
| Modificada | Crítica (9.8) | 1.2% | — | Comfast Cf-xr11 Firmware | 15/8/2023 | 17/6/2026 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt. |