Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.8)0.38%—Rapid7 Insightconnect Markdown PluginAI26/6/202624/7/2026
Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import) embedded in Markdown input. The initial…
AnalizadaMedia (6.9)0.31%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.
AnalizadaAlta (8.8)0.44%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
AnalizadaMedia (6.9)0.40%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.
AnalizadaCrítica (9.3)0.25%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
AnalizadaAlta (8.7)0.39%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
AnalizadaAlta (7.1)0.27%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.
AnalizadaAlta (8.8)0.52%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
AnalizadaMedia (6.9)0.42%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
AnalizadaCrítica (9.3)0.14%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
AnalizadaCrítica (9.2)0.24%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
AnalizadaAlta (8.5)0.18%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
AnalizadaAlta (8.5)1.6%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
AnalizadaAlta (8.8)0.41%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
AnalizadaMedia (6.9)0.27%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
AnalizadaAlta (7.2)0.28%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
AnalizadaAlta (8.8)0.45%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
AnalizadaCrítica (9.4)0.42%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
AnalizadaAlta (8.7)0.42%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
AnalizadaMedia (5.3)0.23%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
AnalizadaCrítica (9.3)0.53%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
AnalizadaCrítica (9.4)0.81%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
AnalizadaAlta (8.5)0.14%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
AnalizadaAlta (8.7)0.63%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
AnalizadaAlta (8.7)0.42%—Acer Connect M6E 5G Firmware4/6/202622/7/2026
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.