Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)1.2%—Meritlilin IP CameraAI12/1/202617/6/2026
Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
AplazadaAlta (8.7)1.2%—Meritlilin DVRAIMeritlilin NVRAI12/1/202617/6/2026
Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
ModificadaCrítica (9.8)1.0%—Meritlilin Ah55b08 FirmwareMeritlilin Ah55b04 Firmware3/1/202317/6/2026
Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.
ModificadaAlta (7.5)1.7%—Meritlilin P2r8852e2 FirmwareMeritlilin P2r8852e4 FirmwareMeritlilin P2r6852e2 FirmwareMeritlilin P2r6852e4 Firmware+3728/4/202117/6/2026
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.
ModificadaCrítica (9.8)2.1%—Meritlilin P2r8852e2 FirmwareMeritlilin P2r8852e4 FirmwareMeritlilin P2r6852e2 FirmwareMeritlilin P2r6852e4 Firmware+3728/4/202117/6/2026
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices.
ModificadaCrítica (9.8)2.4%—Meritlilin P2r8852e2 FirmwareMeritlilin P2r8852e4 FirmwareMeritlilin P2r6852e2 FirmwareMeritlilin P2r6852e4 Firmware+3728/4/202117/6/2026
The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.
ModificadaAlta (7.2)3.8%—Meritlilin P2r8852e2 FirmwareMeritlilin P2r8852e4 FirmwareMeritlilin P2r6852e2 FirmwareMeritlilin P2r6852e4 Firmware+3728/4/202117/6/2026
The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.