Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.0%—Ietf Ipv614/1/202517/6/2026
IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.
ModificadaMedia (6.5)1.0%—Ietf Ipv614/1/202517/6/2026
IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.
AnalizadaMedia (5.3)0.76%—Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv3Nxtech Cente Tcp/ipv4+215/4/202417/6/2026
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.
AnalizadaMedia (5.3)0.54%—Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv315/4/202417/6/2026
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
AnalizadaAlta (7.5)0.61%—Nxtech Cente Ipv6Nxtech Cente Ipv6 Snmpv2Nxtech Cente Ipv6 Snmpv315/4/202417/6/2026
Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.
ModificadaCrítica (9.1)0.56%—Elwsc Kasago Ipv4Elwsc Kasago Ipv4 LightElwsc Kasago Ipv6/v4 DualElwsc Kasago Mobile Ipv610/2/202317/6/2026
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either hijack existing ones or spoof future ones.
ModificadaAlta (7.1)0.81%—Treck Ipv622/12/202017/6/2026
An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows an unauthenticated remote attacker to cause an Out of Bounds Read, and possibly a Denial of Service via adjacent network access.
ModificadaAlta (7.3)1.5%—Treck Ipv622/12/202017/6/2026
An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthenticated remote attacker to cause an Out of Bounds Write, and possibly a Denial of Service via network access.
ModificadaMedia (5.3)1.7%—Treck Ipv622/12/202017/6/2026
An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a packet sent by an unauthenticated remote attacker could result in an out-of-bounds read of up to three bytes via network access.
ModificadaAlta (8.1)1.9%—Plathome Easyblocks Ipv6 FirmwarePlathome Easyblocks Ipv6 Enterprise Firmware8/4/202017/6/2026
Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows remote attackers to impersonate a registered user and log in the management console, that may result in information alteration/disclosure via unspecified vectors.
ModificadaAlta (8.8)0.91%—Plathome Easyblocks Ipv6 FirmwarePlathome Easyblocks Ipv6 Enterprise Firmware8/4/202017/6/2026
Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier and Enterprise Ver. 2.0.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (8.6)2.8%—Ietf Ipv614/1/201717/6/2026
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at length in [RFC6274] and [RFC7739]. An attacker can leverage the…
ModificadaAlta (10)3.0%—Linux-ipv6 Umip13/7/201016/6/2026
Multiple buffer overflows in ha.c in the mipv6 daemon in UMIP 0.4 allow remote attackers to have an unspecified impact via a crafted (1) ND_OPT_PREFIX_INFORMATION or (2) ND_OPT_HOME_AGENT_INFO packet.
ModificadaBaja (2.1)0.34%—Linux-ipv6 Umip13/7/201016/6/2026
The mipv6 daemon in UMIP 0.4 does not verify that netlink messages originated in the kernel, which allows local users to spoof netlink socket communication via a crafted unicast message.
ModificadaAlta (7.8)5.0%—Ietf Ipv625/4/200716/6/2026
The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create network amplification between two routers.