Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.60% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby… | |
| Aplazada | Crítica (9.3) | 0.52% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In… | |
| Aplazada | Media (5.3) | 0.58% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping` function, which is restricted to higher-privileged… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in broken access control has been identified in the /api/v1/setting/data endpoint of the affected device. This flaw allows a low-privileged authenticated user to call the API without the… | |
| Aplazada | Alta (8.7) | 0.51% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploited after a legitimate… | |
| Aplazada | Crítica (9.3) | 1.8% | — | Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI | 3/1/2025 | 17/6/2026 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s… | |
| Aplazada | Alta (8.6) | 1.2% | — | Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI | 3/1/2025 | 17/6/2026 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk. |