Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Hinet Gpon Firmware17/10/201917/6/2026
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 6998. CVSS 3.0 Base score 10.0. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
ModificadaAlta (7.5)1.2%—Hinet Gpon Firmware17/10/201917/6/2026
A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
ModificadaCrítica (9.8)1.4%—Hinet Gpon Firmware17/10/201917/6/2026
HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication.
ModificadaAlta (7.5)1.2%—Hinet Gpon Firmware17/10/201917/6/2026
A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
ModificadaCrítica (9.8)1.3%—Hinet Gpon Firmware17/10/201917/6/2026
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 3097. CVSS 3.0 Base score 10.0. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
ModificadaAlta (7.8)12%—Raisecom Iscom Ht803g-u FirmwareRaisecom Iscom Ht803g-w FirmwareRaisecom Iscom Ht803g-1ge FirmwareRaisecom Iscom Ht803g Gpon Firmware21/3/201917/6/2026
An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below, The values of the newpass and confpass parameters in /bin/WebMGR are used in a system call in the…
ModificadaAlta (7.8)3.5%—Raisecom Iscom Ht803g-u FirmwareRaisecom Iscom Ht803g-w FirmwareRaisecom Iscom Ht803g-1ge FirmwareRaisecom Iscom Ht803g Gpon Firmware21/3/201917/6/2026
An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below. The value of the fmgpon_loid parameter is used in a system call inside the boa binary. Because there…