Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.60%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and change the configuration or execute arbitrary OS commands.
ModificadaAlta (8.8)0.65%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to execute arbitrary OS commands.
ModificadaMedia (6.1)0.79%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Cross-site scripting vulnerability in Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an remote attacker to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)0.47%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier may allow an attacker on the same network segment to access a non-documented developer screen to perform operations on the affected device.
ModificadaMedia (6.5)0.50%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware9/1/201917/6/2026
Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to bypass access restriction to access the information and files stored on the affected device.
ModificadaAlta (8.8)0.77%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaCrítica (9.8)2.0%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
ModificadaCrítica (9.8)1.4%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses hard-coded credentials, which may allow attackers to perform operations on device with administrative privileges.
ModificadaCrítica (9.8)1.5%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to bypass access restriction to change the administrator account password via unspecified vectors.
ModificadaCrítica (9.8)1.8%—Toshiba Hem-gw16a FirmwareToshiba Hem-gw26a Firmware7/7/201717/6/2026
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to access a non-documented developer screen to perform operations on device with administrative privileges.
Orbitaley — Vulnerabilidades