Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.18%—Tp-link Kasa Ec70AITp-link Kasa Ec71AI1/10/20262/10/2026
Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader. Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate…
Pendiente de análisisAlta (8.7)0.20%—Tp-link KasaAI26/8/202628/8/2026
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control. Successful exploitation could allow…
AnalizadaAlta (8.6)0.31%—Tp-link Kasa Ec71 FirmwareTp-link Kasa Ec70 Firmware15/7/20266/8/2026
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to the firmware image can extract the embedded key. Successful exploitation may allow an unauthenticated attacker on the same network to use this key in…
AnalizadaMedia (5.3)0.40%—Tp-link Kasa Ec70 FirmwareTp-link Kasa Ec71 Firmware15/7/20266/8/2026
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted…
AnalizadaAlta (7.7)0.23%—Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+1013/2/202617/6/2026
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel.…
AnalizadaBaja (2)0.36%—Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+1013/2/202617/6/2026
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow…
AplazadaMedia (5.3)0.36%—Vchasno KasaAI19/7/202517/6/2026
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_metabox_action() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to generate invoices for arbitrary orders.
AplazadaMedia (5.3)0.37%—Vchasno KasaAI19/7/202517/6/2026
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to clear log files.
AplazadaMedia (4.3)0.20%—Tp-link Kasa Kp125mAITp-link Tapo P125mAI30/9/202417/6/2026
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.
AplazadaAlta (7.6)0.36%—Tp-link Kasa Kp125mAI30/9/202417/6/2026
An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by other users.
AplazadaMedia (6.3)0.16%—Tp-link Tapo P125mAITp-link Kasa Kp125mAI30/9/202417/6/2026
TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.
ModificadaCrítica (9.1)0.56%—Elwsc Kasago Ipv4Elwsc Kasago Ipv4 LightElwsc Kasago Ipv6/v4 DualElwsc Kasago Mobile Ipv610/2/202317/6/2026
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either hijack existing ones or spoof future ones.