Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6)0.28%—Tp-link Er7212pc FirmwareTp-link Er605 FirmwareTp-link Er7206 FirmwareTp-link Er7406 Firmware+1420/8/20268/9/2026
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow…
AnalizadaMedia (6.3)0.25%—Tp-link Er7212pc FirmwareTp-link Er605 FirmwareTp-link Er7206 FirmwareTp-link Er7406 Firmware+1420/8/20268/9/2026
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may…
AnalizadaCrítica (9.3)5.7%—Tp-link Er7212pc FirmwareTp-link Er605 FirmwareTp-link Er605w FirmwareTp-link Er7206 Firmware+1420/8/20263/9/2026
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing…
AnalizadaMedia (6)0.22%—Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+5223/1/202617/6/2026
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline…