Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnable. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the function formAccept of the file /goform/formAccept. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Performing a manipulation of the argument max_Conn/timeOut results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A flaw has been found in Edimax EW-7438RPn 1.31. This impacts the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component webs. This manipulation of the argument selSSID/submit-url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A vulnerability was detected in Edimax EW-7438RPn 1.31. This affects the function formHwSet of the file /goform/formHwSet. The manipulation of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/initgain/txcck/txofdm/submit-url results in stack-based buffer overflow. The attack can… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The impacted element is the function formWlanMP of the file /goform/formWlanMP. The manipulation of the argument… | |
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Ew-7438rpnAI | 25/5/2026 | 23/7/2026 | A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component Content-Type Handler. Executing a manipulation of the argument… | |
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affects the function formEZCHNwlanSetup of the file /goform/formEZCHNwlanSetu of the component POST Request Handler. Performing a manipulation of the argument method results in command injection. Remote exploitation of the attack is possible. The… | |
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A security vulnerability has been detected in Edimax EW-7438RPn 1.12. This vulnerability affects the function formConnectionSetting of the file /goform/formConnectionSetting of the component Setting Handler. Such manipulation of the argument max_Conn/timeOut leads to command injection. The attack may be launched… | |
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A weakness has been identified in Edimax EW-7438RPn 1.12. This affects the function formAccept of the file /goform/formAccep of the component POST Request Handler. This manipulation of the argument submit-url causes command injection. The attack may be initiated remotely. The exploit has been made available to the… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A security flaw has been discovered in Edimax EW-7438RPn 1.28a. Affected by this issue is the function formwlencrypt24g of the file /goform/formwlencrypt24g of the component POST Request Handler. The manipulation of the argument key1 results in buffer overflow. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 2.4% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by this vulnerability is the function formHwSet of the file /goform/formHwSet of the component POST Request Handler. The manipulation of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/comd/initgain/txcck/txofdm… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A vulnerability was found in Edimax EW-7438RPn up to 1.31. Affected by this vulnerability is an unknown functionality of the file /goform/mp of the component webs. The manipulation of the argument webs results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 3.1% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the component webs. The manipulation of the argument ip/mask/gateway leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A flaw has been found in Edimax EW-7438RPn up to 1.31. This impacts the function formWirelessTbl of the file /goform/formWirelessTbl of the component webs. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A vulnerability was detected in Edimax EW-7438RPn up to 1.31. This affects the function formWizSurvey of the file /goform/formWizSurvey of the component webs. Performing a manipulation of the argument ssid/manualssid/ip/mask/gateway results in buffer overflow. The attack is possible to be carried out remotely. The… | |
| Aplazada | Alta (7.4) | 0.80% | — | Edimax Ew-7438rpnAI | 24/5/2026 | 23/7/2026 | A security vulnerability has been detected in Edimax EW-7438RPn up to 1.31. The impacted element is an unknown function of the file /goform/formWpsStart of the component webs. Such manipulation of the argument pinCode/wlan-url leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 3.1% | — | Edimax Ew-7438rpnAI | 23/5/2026 | 23/7/2026 | A weakness has been identified in Edimax EW-7438RPn up to 1.31. The affected element is the function formWpsStart of the file /goform/formWpsStart of the component webs. This manipulation of the argument pinCode causes os command injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Analizada | Alta (8.7) | 0.80% | — | Edimax Ew-7438rpn Mini Firmware | 5/2/2026 | 17/6/2026 | Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without authentication. |