Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 16% | 💥 Exploit | Dlink Dcs-3411 FirmwareDlink Dcs-3430 FirmwareDlink Dcs-5605 FirmwareDlink Dcs-5635 Firmware+13 | 28/1/2020 | 16/6/2026 | An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU,… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Dlink Dcs-3411 FirmwareDlink Dcs-3430 FirmwareDlink Dcs-5605 FirmwareDlink Dcs-5635 Firmware+13 | 28/1/2020 | 16/6/2026 | An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-2121 1.05_RU/1.06/1.06_FR/1.05_TESCO,… | |
| Modificada | Media (5.3) | 13% | 💥 Exploit | Dlink Dcs-3411 FirmwareDlink Dcs-3430 FirmwareDlink Dcs-5605 FirmwareDlink Dcs-5635 Firmware+13 | 28/1/2020 | 16/6/2026 | An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK WCS-1100 1.02,… | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Dlink Dcs-3411 FirmwareDlink Dcs-3430 FirmwareDlink Dcs-5605 FirmwareDlink Dcs-5635 Firmware+13 | 28/1/2020 | 16/6/2026 | A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00,… | |
| Modificada | Alta (8.8) | 3.8% | — | Dlink Dcs-1100 FirmwareDlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device requires that a user logging into the device provide a username and password. However, the device allows D-Link apps on the mobile devices and desktop to communicate with the device without any authentication. As a part of that communication,… | |
| Modificada | Alta (8.8) | 12% | — | Dlink Dcs-1130 FirmwareDlink Dcs-1100 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and listens for broadcast packets sent on 255.255.255.255. This daemon handles custom D-Link UDP based protocol that allows D-Link mobile applications and desktop applications… | |
| Modificada | Crítica (9.8) | 3.9% | — | Dlink Dcs-1130 FirmwareDlink Dcs-1100 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password retrieved from the user at address… | |
| Modificada | Alta (8.8) | 10% | — | Dlink Dcs-1130 FirmwareDlink Dcs-1100 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and listens for broadcast packets sent on 255.255.255.255. This daemon handles custom D-Link UDP based protocol that allows D-Link mobile applications and desktop applications… | |
| Modificada | Alta (8.8) | 5.7% | — | Dlink Dcs-1130 FirmwareDlink Dcs-1100 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom binary called mp4ts under the /var/www/video folder. It seems that this binary dumps the HTTP VERB in the system logs. As a part of doing that it retrieves the HTTP VERB sent by the user and uses a vulnerable sprintf function at… | |
| Modificada | Alta (7.8) | 1.7% | — | Dlink Dcs-1100 FirmwareDlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary orthrus in /sbin folder of the device handles all the UPnP connections received by the device. It seems that the binary performs a sprintf operation at address 0x0000A3E4 with the value in the command line parameter "-f" and stores it on the… | |
| Modificada | Crítica (9.8) | 5.6% | — | Dlink Dcs-1100 FirmwareDlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary performs a memcpy operation at address 0x00011E34 with the value sent in the "Authorization: Basic" RTSP header and stores it… | |
| Modificada | Alta (7.5) | 2.7% | — | Dlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1130 devices. The device requires that a user logging to the device to provide a username and password. However, the device does not enforce the same restriction on a specific URL thereby allowing any attacker in possession of that to view the live video feed. The severity of this… | |
| Modificada | Alta (8.8) | 1.2% | — | Dlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows an hosted flash file on any domain to make calls to the device's webserver and pull any information that is stored on the device. In this case, user's… | |
| Modificada | Alta (7.5) | 2.7% | — | Dlink Dcs-1100 FirmwareDlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1130 and DCS-1100 devices. The binary rtspd in /sbin folder of the device handles all the rtsp connections received by the device. It seems that the binary loads at address 0x00012CF4 a flag called "Authenticate" that indicates whether a user should be authenticated or not before… | |
| Modificada | Alta (8.8) | 5.9% | — | Dlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the POST parameters passed in this request (to test if email credentials and hostname sent to the device work properly) result in… | |
| Modificada | Alta (8.8) | 1.2% | — | Dlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross-site request forgery protection mechanism which allows an attacker to trick a user who is… | |
| Modificada | Crítica (9.8) | 7.7% | — | Dlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the POST parameters passed in this request (to test if email credentials and hostname sent to the device work properly) result in… | |
| Modificada | Crítica (9.8) | 5.1% | — | Dlink Dcs-1130 Firmware | 2/7/2019 | 17/6/2026 | An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the GET parameters passed in this request (to test if SMB credentials and hostname sent to the device work properly) result in being… |