Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.25%—Netgear Ex2800 FirmwareNetgear Ex3110 FirmwareNetgear Ex5000 FirmwareNetgear Ex6110 Firmware13/1/202617/6/2026
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.
AnalizadaMedia (6.1)0.25%—Netgear Ex5000 FirmwareNetgear Ex3110 FirmwareNetgear Ex6110 FirmwareNetgear Ex2800 Firmware13/1/202617/6/2026
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel.
ModificadaAlta (7.5)74%—Exagrid Ex3000 FirmwareExagrid Ex5000 FirmwareExagrid Ex7000 FirmwareExagrid Ex10000e Firmware+421/4/201717/6/2026
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.
ModificadaCrítica (9.8)72%—Exagrid Ex3000 FirmwareExagrid Ex5000 FirmwareExagrid Ex7000 FirmwareExagrid Ex10000e Firmware+421/4/201717/6/2026
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.