Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6) | 0.26% | — | Openthread Authors OpenthreadAI | 13/5/2026 | 17/6/2026 | Improper Input Validation in the NAT64 translator in The OpenThread Authors OpenThread before commit 26a882d on all platforms allows an attacker on the adjacent IPv4 network to inject corrupted IPv6 packets into the Thread mesh or bypass security checks via crafted IPv4 packets with options. | |
| Aplazada | Media (5.3) | 0.22% | — | Silabs Openthread RCPAI | 25/7/2025 | 17/6/2026 | In high traffic environments, a Silicon Labs OpenThread RCP (see impacted versions) fails to clear the SPI transmit buffer and may send a corrupt packet over SPI to its host, causing the host to reset the RCP which results in a denial of service. | |
| Aplazada | Media (6.5) | 0.27% | — | Openthread Border RouterAISilabs Multi Protocol GatewayAI | 27/6/2024 | 17/6/2026 | In a Silicon Labs multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task running on the host platform to crash, allowing an attacker to cause a temporary denial-of-service. | |
| Modificada | Crítica (9.1) | 0.21% | — | Silabs Openthread SDK | 26/10/2023 | 17/6/2026 | Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored in flash. This issue affects Silicon Labs OpenThread SDK: 2.3.1 and earlier. | |
| Modificada | Media (6.8) | 0.69% | — | TI 15.4-stackTI Ble5-stackDynamic Multi-protocal ManagerTI Easylink+3 | 20/9/2021 | 17/6/2026 | TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing to pair with a… | |
| Modificada | Media (6.8) | 0.33% | — | Openthread Wpantund | 2/7/2021 | 17/6/2026 | OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data type for metric_len. | |
| Modificada | Media (5.5) | 0.27% | — | Openthread Wpantund | 7/7/2020 | 17/6/2026 | A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the control driver (eg: debug environments) can allow an attacker to crash the service (DoS). We recommend updating, or to restrict access in… | |
| Modificada | Crítica (9.8) | 0.88% | — | Google Openthread | 28/4/2020 | 17/6/2026 | OpenThread before 2019-12-13 has a stack-based buffer overflow in MeshCoP::Commissioner::GeneratePskc. |