Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.40% | — | Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+19 | 26/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl,… | |
| Aplazada | Media (5.1) | 0.22% | — | Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+19 | 26/4/2025 | 17/6/2026 | A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000… | |
| Modificada | Alta (7.2) | 19% | — | Gl-inet Gl-e750 Firmware | 21/6/2023 | 17/6/2026 | A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request. | |
| Modificada | Crítica (9.8) | 14% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer. | |
| Modificada | Media (4.9) | 3.9% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters… | |
| Modificada | Alta (7.5) | 0.94% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 10/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the… | |
| Modificada | Alta (7.5) | 30% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key. | |
| Modificada | Alta (7.5) | 0.82% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to obtain a list of files in a specific directory, by using the regex feature in a package name. | |
| Modificada | Alta (7.5) | 20% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. |