Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.57%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the web_exec parameter at /apply.cgi.
ModificadaAlta (7.5)1.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file read via the function sub_177E0.
ModificadaCrítica (9.1)1.4%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the function sub_17C08.
ModificadaCrítica (9.8)3.6%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.5%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.8%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted packet.
ModificadaCrítica (9.8)3.8%—Inhandnetworks Inrouter 900 Firmware10/4/202217/6/2026
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a crafted packet.
Orbitaley — Vulnerabilidades