Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.60%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby…
AplazadaCrítica (9.3)0.52%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In…
AplazadaMedia (5.3)0.58%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping` function, which is restricted to higher-privileged…
AplazadaCrítica (9.3)0.66%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in broken access control has been identified in the /api/v1/setting/data endpoint of the affected device. This flaw allows a low-privileged authenticated user to call the API without the…
AplazadaAlta (8.7)0.51%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploited after a legitimate…
AplazadaCrítica (9.3)1.8%—Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI3/1/202517/6/2026
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s…
AplazadaAlta (8.6)1.2%—Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI3/1/202517/6/2026
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.