Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 1.3% | — | Netis Ac1200 Router Nc21AI | 27/5/2026 | 5/7/2026 | Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to the underlying OS shell without sanitization. An attacker can inject arbitrary shell commands by wrapping them in… | |
| Aplazada | Alta (7.3) | 0.37% | — | Netis Ac1200 Router Nc21AI | 27/5/2026 | 17/6/2026 | Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with no authentication required. Any attacker on the LAN can send a single HTTP GET request and instantly retrieve administrator credentials, WiFi passwords, PPPoE… | |
| Aplazada | Alta (7.3) | 0.30% | — | Netis Ac1200 Router Nc21AI | 27/5/2026 | 5/7/2026 | Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to the trivially weak value root, allowing an attacker with access to the device to authenticate as root and gain full control of the underlying operating system. | |
| Aplazada | Alta (7.5) | 3.1% | — | Netis Nx10AINetis Nc65AINetis Nc63AINetis Nc21AI+1 | 6/1/2025 | 17/6/2026 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to… | |
| Aplazada | Alta (7.5) | 17% | — | Netis Nx10AINetis Nc65AINetis Nc63AINetis Nc21AI+1 | 6/1/2025 | 17/6/2026 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to… | |
| Aplazada | Baja (2.7) | 6.4% | — | Netis Wifi6 Router Nx10AINetis Wifi 11ac Router Nc65AINetis Wifi 11ac Router Nc63AINetis Wifi 11ac Router Nc21AI+1 | 6/1/2025 | 17/6/2026 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to… | |
| Modificada | Alta (8.1) | 0.92% | — | Kalkitech Sync241-m1 FirmwareKalkitech Sync241-m2 FirmwareKalkitech Sync241-m4 FirmwareKalkitech Sync261-m1 Firmware+16 | 6/1/2022 | 17/6/2026 | A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and… | |
| Modificada | Alta (8.8) | 2.2% | — | Tp-link Nc200 FirmwareTp-link Nc210 FirmwareTp-link Nc220 FirmwareTp-link Nc230 Firmware+3 | 17/6/2020 | 17/6/2026 | TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a… | |
| Modificada | Alta (8.8) | 74% | — | Tp-link Nc200 FirmwareTp-link Nc210 FirmwareTp-link Nc220 FirmwareTp-link Nc230 Firmware+3 | 4/5/2020 | 17/6/2026 | Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304. | |
| Modificada | Crítica (9.8) | 14% | — | Tp-link Nc200 FirmwareTp-link Nc210 FirmwareTp-link Nc220 FirmwareTp-link Nc230 Firmware+3 | 4/5/2020 | 17/6/2026 | Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304. | |
| Modificada | Alta (7.5) | 3.8% | — | Tp-link Nc450 FirmwareTp-link Nc260 FirmwareTp-link Nc250 FirmwareTp-link Nc230 Firmware+3 | 1/4/2020 | 17/6/2026 | TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_Build_190805, and NC450 through 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference. | |
| Modificada | Media (5.3) | 1.8% | — | Tp-link Nc450 FirmwareTp-link Nc260 FirmwareTp-link Nc250 FirmwareTp-link Nc230 Firmware+11 | 1/4/2020 | 17/6/2026 | TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855. |