Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.6) | 0.56% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientID parameters. An unauthorized user could calculate this parameter and use it to… | |
| Modificada | Alta (8.1) | 0.49% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-284: Improper Access Control. They allow unauthenticated devices to subscribe to MQTT topics on the same network as the device manager. An unauthorized user who knows… | |
| Modificada | Crítica (9.1) | 0.32% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-760: Use of a One-way Hash with a Predictable Salt. They send MQTT credentials in response to HTTP/HTTPS requests from the cloud platform. These credentials are encoded… | |
| Modificada | Alta (7.2) | 1.6% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). An unauthorized user with privileged access to the local web interface… | |
| Modificada | Media (5.9) | 0.51% | — | Inhandnetworks Inrouter302 FirmwareInhandnetworks Inrouter615-s Firmware | 12/1/2023 | 17/6/2026 | InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-319: Cleartext Transmission of Sensitive Information. They use an unsecured channel to communicate with the cloud platform by default. An unauthorized user could… | |
| Modificada | Crítica (9.8) | 0.67% | — | Inhandnetworks Inrouter302 Firmware | 9/11/2022 | 17/6/2026 | The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability. | |
| Modificada | Alta (8.1) | 1.8% | — | Inhandnetworks Inrouter302 Firmware | 12/5/2022 | 17/6/2026 | A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability. | |
| Modificada | Media (6.1) | 1.5% | — | Inhandnetworks Inrouter302 Firmware | 12/5/2022 | 17/6/2026 | A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.0% | — | Inhandnetworks Inrouter302 Firmware | 12/5/2022 | 17/6/2026 | A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability. |