Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7) | 0.11% | — | Semtech Lr11xxAI | 7/4/2026 | 24/7/2026 | The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device can exploit this… | |
| Pendiente de análisis | Media (5.1) | 0.11% | — | Semtech Lr11xxAI | 7/4/2026 | 24/7/2026 | The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability in its firmware validation functionality. When a host issues a firmware validity check command via the SPI interface, the device decrypts the provided encrypted firmware package block-by-block to… | |
| Pendiente de análisis | Media (5.4) | 0.24% | — | Semtech Lora Lr11xxxAI | 7/4/2026 | 24/7/2026 | An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. An attacker with physical access to the SPI interface can… | |
| Modificada | Crítica (9.8) | 0.68% | — | Mediatek Lr11Mediatek Lr12aMediatek Lr13Mediatek Nr15+2 | 2/10/2023 | 17/6/2026 | In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: MOLY01068234; Issue ID: ALPS08010003. | |
| Modificada | Crítica (9.8) | 3.4% | — | Mediatek Lr11Mediatek Lr12Mediatek Lr12aMediatek Lr13+3 | 6/7/2022 | 17/6/2026 | In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | |
| Modificada | Crítica (9.8) | 2.8% | — | Mediatek Lr11Mediatek Lr12Mediatek Lr12aMediatek Lr13+3 | 6/7/2022 | 17/6/2026 | In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00803883; Issue ID: MOLY00803883. | |
| Modificada | Alta (7.5) | 0.74% | — | Mediatek L9Mediatek Lr11Mediatek Lr12Mediatek Lr12a+2 | 4/1/2022 | 17/6/2026 | In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID: ALPS05886933. |