Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.12% | — | Eufy Homebase 2AI | 25/3/2026 | 17/6/2026 | An issue in Eufy Homebase 2 version 3.3.4.1h allows a local attacker to obtain sensitive information via the cryptographic scheme. | |
| Modificada | Alta (8.2) | 0.23% | — | Eufy Homebase 2 Firmware | 3/10/2024 | 5/7/2026 | The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serves as a proxy to the end user's primary network. The WPA2-PSK generation of this dedicated network is flawed and solely based on the serial number. Due to the flawed generation process, the WPA2-PSK… | |
| Modificada | Crítica (9.8) | 1.3% | — | UclibcUclibc-ng Project Uclibc-ngAnker Eufy Homebase 2 Firmware | 29/9/2022 | 17/6/2026 | A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 2.3% | — | Anker Eufy Homebase 2 Firmware | 17/6/2022 | 17/6/2026 | A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network. | |
| Modificada | Media (6.5) | 0.72% | — | Anker Eufy Homebase 2 Firmware | 5/5/2022 | 17/6/2026 | A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to a device reboot. An attacker can send packets to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 1.0% | — | Anker Eufy Homebase 2 Firmware | 5/5/2022 | 17/6/2026 | An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 0.98% | — | Anker Eufy Homebase 2 Firmware | 22/12/2021 | 17/6/2026 | An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted man-in-the-middle attack can lead to increased privileges. | |
| Modificada | Crítica (9.8) | 1.3% | — | Anker Eufy Homebase 2 Firmware | 22/12/2021 | 17/6/2026 | An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to increased privileges. | |
| Modificada | Alta (7.5) | 1.0% | — | Anker Eufy Homebase 2 Firmware | 9/12/2021 | 17/6/2026 | An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability. | |
| Modificada | Crítica (9.9) | 2.5% | — | Anker Eufy Homebase 2 Firmware | 9/12/2021 | 17/6/2026 | A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary command execution. | |
| Modificada | Crítica (10) | 2.5% | — | Anker Eufy Homebase 2 Firmware | 8/12/2021 | 17/6/2026 | An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted network packet can lead to code execution. | |
| Modificada | Crítica (10) | 2.5% | — | Anker Eufy Homebase 2 Firmware | 8/12/2021 | 17/6/2026 | An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_response_msg_process. A specially-crafted network packet can lead to code execution. | |
| Modificada | Crítica (9) | 1.7% | — | Anker Eufy Homebase 2 Firmware | 12/10/2021 | 17/6/2026 | A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to remote code execution. | |
| Modificada | Crítica (10) | 1.3% | — | Anker Eufy Homebase 2 Firmware | 12/10/2021 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. |