Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.65% | — | Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+18 | 17/7/2024 | 17/6/2026 | FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition. | |
| Modificada | Alta (8.8) | 0.62% | — | Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+18 | 17/7/2024 | 17/6/2026 | FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed. | |
| Modificada | Crítica (9.1) | 0.75% | — | Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+18 | 17/7/2024 | 17/6/2026 | Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly. | |
| Modificada | Alta (8.8) | 0.37% | — | Fujitsu Si-r 30B FirmwareFujitsu Si-r 130b FirmwareFujitsu Si-r 90brin FirmwareFujitsu Si-r570b Firmware+12 | 26/7/2023 | 17/6/2026 | Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected products and versions are as follows: Si-R 30B all versions, Si-R 130B all versions,… | |
| Modificada | Alta (7.8) | 4.8% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+61 | 24/5/2022 | 17/6/2026 | A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00… | |
| Modificada | Alta (7.8) | 6.2% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+61 | 24/5/2022 | 17/6/2026 | Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions… | |
| Modificada | Alta (8.1) | 0.94% | — | Meross Msg100 Firmware | 7/10/2021 | 17/6/2026 | Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who sniffs a Close message can transmit an acceptable Open message). | |
| Modificada | Crítica (9.8) | 2.3% | — | Zyxel Usg1900 FirmwareZyxel Usg1100 FirmwareZyxel Usg310 FirmwareZyxel Usg210 Firmware+33 | 2/7/2021 | 17/6/2026 | An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device. | |
| Modificada | Alta (7.5) | 1.3% | — | Asus Hg100 FirmwareAsus Mw100 FirmwareAsus Ws-101 FirmwareAsus Ts-101 Firmware+3 | 20/12/2019 | 17/6/2026 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks. | |
| Modificada | Crítica (9.8) | 0.84% | — | Asus Hg100 FirmwareAsus Mw100 FirmwareAsus Ws-101 FirmwareAsus Ts-101 Firmware+3 | 20/12/2019 | 17/6/2026 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages. | |
| Modificada | Alta (7.5) | 1.3% | — | Asus Hg100 FirmwareAsus Mw100 FirmwareAsus Ws-101 FirmwareAsus Ts-101 Firmware+3 | 20/12/2019 | 17/6/2026 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack. | |
| Modificada | Media (5.5) | 0.29% | — | Symphony-mobile G100 Firmware | 14/11/2019 | 17/6/2026 | The Symphony G100 Android device with a build fingerprint of Symphony/G100/G100:8.1.0/O11019/1530618779:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an… | |
| Modificada | Alta (8.1) | 4.0% | — | Asus Hg100 Firmware | 29/8/2019 | 17/6/2026 | A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability… | |
| Modificada | Alta (7.5) | 3.0% | — | Asus Hg100 Firmware | 29/8/2019 | 17/6/2026 | The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections and associated resources alive for a long period of time. CVSS 3.0 Base score… | |
| Modificada | Media (6.1) | 0.79% | — | Schneider-electric Tsxetg100 Firmware | 22/5/2019 | 17/6/2026 | A CWE-79 Cross-Site Scripting vulnerability exists in all versions of the TSXETG100 allowing an attacker to send a specially crafted URL with an embedded script to a user that would then be executed within the context of that user. | |
| Modificada | Alta (7.5) | 11% | — | Asus Hg100 Firmware | 10/8/2018 | 17/6/2026 | ASUS HG100 devices allow denial of service via an IPv4 packet flood. | |
| Modificada | Crítica (9.8) | 6.7% | — | Asus Hg100 Firmware | 25/7/2018 | 17/6/2026 | ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution. | |
| Modificada | Alta (8.8) | 0.73% | — | Sony Pcs-xg100 FirmwareSony Pcs-xg77 FirmwareSony Pcs-xc1 Firmware | 9/6/2017 | 17/6/2026 | Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firmware version prior to Ver.1.22 allow an attacker on the same network segment to bypass authentication to perform administrative operations via unspecified vectors. |