Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)2.5%—Tp-link Archer Axe75 Firmware31/7/20267/8/2026
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special…
AnalizadaAlta (8.5)1.5%—Tp-link Archer Axe75 Firmware9/3/202617/6/2026
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the router is configured with sysmode=ap. Successful exploitation results in root-level privileges and…
AnalizadaMedia (6.9)0.30%—Tp-link Archer Axe75 Firmware9/1/202617/6/2026
Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects Archer AXE75 v1.6: ≤ build 20250107.
ModificadaAlta (8.8)1.1%—Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware+111/1/202417/6/2026
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
ModificadaAlta (8)0.45%—Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Archer Axe75 Firmware11/1/202417/6/2026
Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.
ModificadaMedia (6.5)0.60%—Sony R5C FirmwareSony Wd75 FirmwareSony Wd65 FirmwareSony Xe70 Firmware+419/6/201917/6/2026
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices has a Buffer Overflow.
ModificadaAlta (8.1)0.89%—Sony R5C FirmwareSony Wd75 FirmwareSony Wd65 FirmwareSony Xe70 Firmware+419/6/201917/6/2026
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.
ModificadaAlta (8.8)0.91%—Sony R5C FirmwareSony Wd75 FirmwareSony Wd65 FirmwareSony Xe70 Firmware+419/6/201917/6/2026
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.
ModificadaAlta (7.2)0.31%—Nokia E75 FirmwareNokia E7529/3/201116/6/2026
The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.
Orbitaley — Vulnerabilidades