Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.6% | — | Hinet Gpon Firmware | 17/10/2019 | 17/6/2026 | An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 6998. CVSS 3.0 Base score 10.0. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). | |
| Modificada | Alta (7.5) | 1.2% | — | Hinet Gpon Firmware | 17/10/2019 | 17/6/2026 | A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L). | |
| Modificada | Crítica (9.8) | 1.4% | — | Hinet Gpon Firmware | 17/10/2019 | 17/6/2026 | HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication. | |
| Modificada | Alta (7.5) | 1.2% | — | Hinet Gpon Firmware | 17/10/2019 | 17/6/2026 | A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L). | |
| Modificada | Crítica (9.8) | 1.3% | — | Hinet Gpon Firmware | 17/10/2019 | 17/6/2026 | An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 3097. CVSS 3.0 Base score 10.0. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). | |
| Modificada | Alta (7.8) | 12% | — | Raisecom Iscom Ht803g-u FirmwareRaisecom Iscom Ht803g-w FirmwareRaisecom Iscom Ht803g-1ge FirmwareRaisecom Iscom Ht803g Gpon Firmware | 21/3/2019 | 17/6/2026 | An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below, The values of the newpass and confpass parameters in /bin/WebMGR are used in a system call in the… | |
| Modificada | Alta (7.8) | 3.5% | — | Raisecom Iscom Ht803g-u FirmwareRaisecom Iscom Ht803g-w FirmwareRaisecom Iscom Ht803g-1ge FirmwareRaisecom Iscom Ht803g Gpon Firmware | 21/3/2019 | 17/6/2026 | An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below. The value of the fmgpon_loid parameter is used in a system call inside the boa binary. Because there… |