Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.78% | — | Linksys E8450AI | 27/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the function set_device_language of the file portal.cgi of the component HTTP POST Request Handler. The manipulation of the argument dut_language leads to buffer overflow. It is possible to initiate the… | |
| Analizada | Media (5.5) | 0.43% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification. | |
| Analizada | Media (5.5) | 0.43% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the stack without length verification. | |
| Analizada | Media (5.5) | 0.43% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the stack without length verification. | |
| Analizada | Alta (8.8) | 1.8% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn. | |
| Analizada | Media (5.5) | 0.45% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to the stack without length verification. | |
| Analizada | Media (6.5) | 0.72% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack without length verification. | |
| Analizada | Alta (8.2) | 1.4% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail. | |
| Analizada | Media (6.5) | 0.72% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_protect_status) is copied to the stack without length verification. | |
| Analizada | Media (6.3) | 0.43% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack without length verification. | |
| Analizada | Alta (8) | 1.5% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status. | |
| Modificada | Alta (8.8) | 11% | — | Linksys E8450 Firmware | 16/4/2023 | 17/6/2026 | Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page. |