Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.65% | — | Openwrt Luci-app-advanced-rebootAI | 21/9/2026 | 24/9/2026 | luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in… | |
| Aplazada | Alta (8.8) | 0.49% | — | Openwrt Luci-app-adblock-fastAI | 21/9/2026 | 29/9/2026 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as… | |
| Aplazada | Alta (8.8) | 0.78% | — | Openwrt Luci-app-https-dns-proxyAI | 27/8/2026 | 1/9/2026 | An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter | |
| Aplazada | Crítica (9.3) | 0.93% | — | Openwrt UhttpdAI | 25/8/2026 | 3/9/2026 | The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username… | |
| Aplazada | Media (6.9) | 0.11% | — | Luci-lib-px5gAIOpenwrtAI | 22/8/2026 | 24/9/2026 | luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255 bytes, but the payload written after… | |
| Aplazada | Alta (7.3) | 3.7% | — | Baicells Eg3661mAIOpenwrt LuciAI | 14/8/2026 | 18/8/2026 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly… | |
| Aplazada | Crítica (9.4) | 0.62% | — | Openwrt Luci-app-lxcAIOpenwrtAI | 13/8/2026 | 30/9/2026 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control… | |
| Aplazada | Alta (8.7) | 0.44% | — | Openwrt LuciAIOpenwrt Luci-mod-system-mountsAI | 13/8/2026 | 30/9/2026 | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default… | |
| Aplazada | Crítica (9.3) | 0.79% | — | Zbtlink Router FirmwareAIOpenwrtAI | 5/8/2026 | 9/9/2026 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's… | |
| Aplazada | Alta (8.7) | 3.3% | — | Openwrt Luci-app-dockermanAIOpenwrtAI | 3/8/2026 | 9/9/2026 | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the… | |
| Aplazada | Alta (8.7) | 0.93% | — | Openwrt Luci-app-bmx7AI | 3/8/2026 | 9/9/2026 | OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the… | |
| Analizada | Media (4.9) | 0.52% | — | Openwrt | 15/7/2026 | 21/7/2026 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing traversal such as an allowed wildcard… | |
| Analizada | Crítica (9.6) | 0.58% | — | Openwrt | 15/7/2026 | 21/7/2026 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and statefiles_write_state4() without escaping, allowing newline injection of forged lease lines that LuCI… | |
| Pendiente de análisis | Crítica (9.4) | 1.3% | — | Openwrt LuciAI | 12/7/2026 | 14/7/2026 | LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages. | |
| Aplazada | Alta (8.7) | 0.68% | — | Openwrt Luci-app-samba4AISambaAI | 12/7/2026 | 30/9/2026 | OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command… | |
| Analizada | Media (6.5) | 0.68% | — | Openwrt | 7/7/2026 | 10/7/2026 | OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The message length underflows before a bounds… | |
| Aplazada | Alta (7.7) | 0.80% | — | Openwrt Luci-app-travelmateAIOpenwrt TravelmateAI | 2/7/2026 | 28/8/2026 | luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only… | |
| Aplazada | Alta (8.7) | 2.7% | — | Openwrt Luci-proto-openvpnAI | 29/6/2026 | 14/7/2026 | luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN protocol configuration access can inject… | |
| Aplazada | Alta (8.7) | 7.8% | — | Openwrt Luci-app-https-dns-proxyAI | 26/5/2026 | 24/7/2026 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the… | |
| Analizada | Media (4.8) | 0.29% | — | Openwrt LuciOpenwrt | 19/3/2026 | 17/6/2026 | LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without any sanitization. The wireless.js file in the luci-mod-network package passes SSIDs via a template… | |
| Analizada | Baja (1.8) | 0.34% | — | Openwrt | 19/3/2026 | 17/6/2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass environment variable filtering and inject an arbitrary PATH variable, potentially leading to privilege escalation. The function is intended to… | |
| Analizada | Baja (2.4) | 0.65% | — | Openwrt | 19/3/2026 | 17/6/2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, the jp_get_token function, which performs lexical analysis by breaking input expressions into tokens, contains a memory leak vulnerability when extracting string literals, field labels, and regular… | |
| Analizada | Crítica (9.5) | 1.1% | — | Openwrt | 19/3/2026 | 17/6/2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS domains (.ip6.arpa) received via multicast… | |
| Analizada | Crítica (9.5) | 0.67% | — | Openwrt | 19/3/2026 | 17/6/2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.arpa). DNS packets… | |
| Analizada | Media (4.6) | 0.12% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+1 | 2/3/2026 | 17/6/2026 | In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID:… |