Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 1.8% | — | Wavlink Wl-wn535k3 Firmware | 2/9/2025 | 17/6/2026 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Analizada | Media (6.5) | 1.1% | — | Wavlink Wl-wn535k3 Firmware | 2/9/2025 | 17/6/2026 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Analizada | Crítica (9.8) | 1.8% | — | Wavlink Wn535k3 Firmware | 14/7/2025 | 17/6/2026 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Modificada | Crítica (9.8) | 34% | — | Wavlink Wl-wn535k2 FirmwareWavlink Wl-wn535k3 Firmware | 20/7/2022 | 17/6/2026 | A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used. | |
| Modificada | Crítica (9.8) | 80% | — | Wavlink Wl-wn535k2 FirmwareWavlink Wl-wn535k3 Firmware | 20/7/2022 | 17/6/2026 | A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection. The exploit has been disclosed to the public and may be used. | |
| Modificada | Crítica (9.8) | 31% | — | Wavlink Wl-wn535k2 FirmwareWavlink Wl-wn535k3 Firmware | 20/7/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used. | |
| Modificada | Alta (8.4) | 0.77% | — | Phicomm K2 FirmwarePhicomm K3 FirmwarePhicomm K3C FirmwarePhicomm K2G Firmware+1 | 10/3/2022 | 17/6/2026 | A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair of ephemeral passwords that allow a user to spawn a telnet service on the router, and to ensure that the telnet service persists upon reboot. By means of a crafted exchange of UDP packets, an… | |
| Modificada | Alta (8.1) | 0.99% | — | Phicomm K2 FirmwarePhicomm K3 FirmwarePhicomm K3C FirmwarePhicomm K2G Firmware+1 | 10/3/2022 | 17/6/2026 | The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated attacker on the local area network to achieve a significant degree of control over the "plaintext" to which an arbitrary blob of ciphertext will be decrypted by OpenSSL's RSA_public_decrypt() function.… | |
| Modificada | Media (5.3) | 1.1% | — | Phicomm K2 FirmwarePhicomm K3 FirmwarePhicomm K3C FirmwarePhicomm K2G Firmware+1 | 10/3/2022 | 17/6/2026 | Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then prevented from accessing either the WAN or the router itself. | |
| Modificada | Alta (7.4) | 1.5% | — | Phicomm K2 FirmwarePhicomm K3 FirmwarePhicomm K3C FirmwarePhicomm K2G Firmware+1 | 10/3/2022 | 17/6/2026 | Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensitive information concerning devices on the local area network, including IP and MAC addresses. Improper access control on the wirelesssetup.asp interface allows an unauthenticated remote attacker to… | |
| Modificada | Media (6.8) | 0.37% | — | Phicomm K2 FirmwarePhicomm K3 FirmwarePhicomm K3C FirmwarePhicomm K2G Firmware+1 | 10/3/2022 | 17/6/2026 | Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unauthenticated Das U-Boot BIOS shell. | |
| Modificada | Alta (8.8) | 0.45% | — | Elecom Wrh-300bk3 FirmwareElecom Wrh-300wh3 FirmwareElecom Wrh-300bk3-s FirmwareElecom Wrh-300wh3-s Firmware+4 | 8/2/2022 | 17/6/2026 | Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v1.05 and earlier, WRH-300LB3-S firmware v1.05 and earlier, WRH-300PN3-S firmware v1.05 and earlier, WRH-300WH3-S… | |
| Modificada | Alta (7.5) | 1.3% | — | Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+51 | 7/10/2020 | 17/6/2026 | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. | |
| Modificada | Media (6.7) | 0.33% | — | Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+168 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. | |
| Modificada | Media (6.7) | 0.33% | — | Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+47 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. | |
| Modificada | Media (5.3) | 1.1% | — | Cobham SEA TEL Coastal 18 FirmwareCobham Sailor 600 Vsat KU FirmwareCobham Sailor 800 Vsat FirmwareCobham Sailor 900 Vsat Firmware+7 | 15/9/2019 | 17/6/2026 | Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latitude and longitude, via the public SNMP community. |