Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.3% | — | Linksys E5600 Firmware | 23/12/2025 | 17/6/2026 | linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. | |
| Analizada | Crítica (9.8) | 1.3% | — | Linksys E5600 Firmware | 23/12/2025 | 17/6/2026 | Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. | |
| Analizada | Media (6.1) | 0.19% | — | Linksys E5600 Firmware | 16/12/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters. | |
| Analizada | Alta (7.5) | 0.53% | — | Linksys E5600 Firmware | 19/8/2025 | 17/6/2026 | A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. The attack requires a high level of complexity. The… | |
| Analizada | Crítica (9.8) | 1.9% | — | Linksys E5600 Firmware | 6/5/2025 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter. | |
| Analizada | Crítica (9.8) | 1.8% | — | Linksys E5600 Firmware | 6/5/2025 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter. | |
| Analizada | Crítica (9.8) | 1.8% | — | Linksys E5600 Firmware | 6/5/2025 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter. | |
| Analizada | Crítica (9.8) | 12% | — | Linksys E5600 Firmware | 6/5/2025 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter. | |
| Analizada | Crítica (9.8) | 11% | — | Linksys E5600 Firmware | 6/5/2025 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function. | |
| Analizada | Alta (8.6) | 0.78% | — | Linksys E5600 Firmware | 21/3/2025 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter. | |
| Analizada | Media (6.3) | 0.66% | — | Linksys E5600 Firmware | 21/3/2025 | 17/6/2026 | In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter. | |
| Analizada | Media (6.3) | 0.66% | — | Linksys E5600 Firmware | 21/3/2025 | 17/6/2026 | In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter. | |
| Analizada | Media (6.3) | 0.66% | — | Linksys E5600 Firmware | 21/3/2025 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function. | |
| Analizada | Media (4.8) | 0.31% | — | Linksys E5600 Firmware | 15/1/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter. | |
| Analizada | Media (4.8) | 0.31% | — | Linksys E5600 Firmware | 15/1/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter. | |
| Analizada | Alta (7.5) | 0.42% | — | Linksys E5600 Firmware | 28/5/2024 | 17/6/2026 | An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service. | |
| Analizada | Alta (8) | 1.9% | — | Linksys E5600 Firmware | 6/5/2024 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint. | |
| Analizada | Crítica (9.8) | 2.4% | — | Linksys E5600 Firmware | 3/5/2024 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint. |