Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.22% | — | Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+52 | 23/1/2026 | 17/6/2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline… | |
| Modificada | Alta (8.7) | 0.67% | — | Tp-link Fr307-m2 FirmwareTp-link Fr205 FirmwareTp-link Fr365 FirmwareTp-link G611 Firmware+9 | 21/10/2025 | 17/6/2026 | An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. | |
| Modificada | Crítica (9.3) | 3.3% | — | Tp-link Er8411 FirmwareTp-link Er7412-m2 FirmwareTp-link Er707-m2 FirmwareTp-link Er7206 Firmware+9 | 21/10/2025 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. | |
| Analizada | Crítica (9.3) | 1.0% | — | Tp-link Er8411 FirmwareTp-link Er7412-m2 FirmwareTp-link Er707-m2 FirmwareTp-link Er7206 Firmware+9 | 21/10/2025 | 17/6/2026 | An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. | |
| Analizada | Alta (8.6) | 0.69% | — | Tp-link Er706w FirmwareTp-link Er706w-4g FirmwareTp-link Er7212pc FirmwareTp-link G36 Firmware+9 | 21/10/2025 | 17/6/2026 | An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. |