Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)3.6%—Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+228/1/202517/6/2026
Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.
ModificadaCrítica (9.8)2.2%—Dlink Dsr-500n Firmware23/8/202117/6/2026
D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in recovering the cleartext password of the identified hash value, he will be able to log in via SSH or Telnet and thus gain access to the underlying embedded Linux operating…
ModificadaAlta (8.8)2.3%—Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+615/12/202017/6/2026
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.
ModificadaAlta (8.8)1.3%—Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+615/12/202017/6/2026
An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. These entries are executed as root.
ModificadaAlta (8.8)2.1%—Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+615/12/202017/6/2026
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with firmware 3.14 and 3.17.
ModificadaCrítica (9.8)9.8%—Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+411/2/202016/6/2026
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the…
ModificadaMedia (4.9)0.66%—Dlink Dsr-150 FirmwareDlink Dsr-150Dlink Dsr-250 FirmwareDlink Dsr-250+1119/12/201317/6/2026
D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 stores account passwords in cleartext, which allows local users to obtain sensitive information by reading…
ModificadaAlta (7.8)1.9%—Dlink Dsr-500 FirmwareDlink Dsr-500Dlink Dsr-150n FirmwareDlink Dsr-150n+1119/12/201317/6/2026
D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 have a hardcoded account of username gkJ9232xXyruTRmY, which makes it easier for remote attackers to obtain…
ModificadaAlta (10)6.5%—Dlink Dsr-500 FirmwareDlink Dsr-500Dlink Dsr-150n FirmwareDlink Dsr-150n+1119/12/201316/6/2026
The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allows remote attackers to execute arbitrary commands via…