Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.33% | — | Gncc GP5AI | 4/6/2026 | 22/7/2026 | GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack. | |
| Aplazada | Media (4.6) | 0.20% | — | Gncc GP5AI | 4/6/2026 | 22/7/2026 | A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot session via a bind-mount attack. | |
| Aplazada | Media (4.6) | 0.21% | — | Gncc GP5AI | 4/6/2026 | 22/7/2026 | The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive user data. | |
| Aplazada | Alta (7.1) | 0.13% | — | Gncc GP5AIBackblaze B2AI | 4/6/2026 | 22/7/2026 | GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface. | |
| Aplazada | Media (6.8) | 0.29% | — | Gncc GP5AIDenx U-bootAI | 4/6/2026 | 22/7/2026 | An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments. | |
| Aplazada | Media (4.6) | 0.20% | — | Gncc GP5AI | 4/6/2026 | 22/7/2026 | GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximate attackers to obtain sensitive information, including network credentials, via monitoring the serial UART interface. | |
| Modificada | Media (6.8) | 0.40% | — | Gncchome Gncc C2 Firmware | 15/8/2024 | 17/6/2026 | Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port. | |
| Modificada | Media (4.6) | 0.26% | — | Gncchome Gncc C2 Firmware | 15/8/2024 | 17/6/2026 | Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port. | |
| Analizada | Media (6.8) | 0.36% | — | Gncchome Gncc C2 Firmware | 15/8/2024 | 17/6/2026 | Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices |