Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.55% | — | Onsemi Qhs710 FirmwareOnsemi Qsr10ga FirmwareOnsemi Qsr10gu FirmwareOnsemi Qv840 Firmware+14 | 8/6/2025 | 17/6/2026 | The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the… | |
| Analizada | Alta (7.8) | 0.94% | — | Onsemi Qcs-ax3-s5 FirmwareOnsemi Qcs-ax2-a12 FirmwareOnsemi Qcs-ax2-t12 FirmwareOnsemi Qcs-ax2-t8 Firmware+14 | 8/6/2025 | 17/6/2026 | The Quantenna Wi-Fi chipset ships with a local control script, set_tx_pow, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This… | |
| Analizada | Alta (7.8) | 0.60% | — | Onsemi Qcs-ax3-s5 FirmwareOnsemi Qcs-ax2-a12 FirmwareOnsemi Qcs-ax2-t12 FirmwareOnsemi Qcs-ax2-t8 Firmware+14 | 8/6/2025 | 17/6/2026 | The Quantenna Wi-Fi chipset ships with a local control script, transmit_file, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This… | |
| Analizada | Alta (7.8) | 0.60% | — | Onsemi Qcs-ax3-s5 FirmwareOnsemi Qcs-ax2-a12 FirmwareOnsemi Qcs-ax2-t12 FirmwareOnsemi Qcs-ax2-t8 Firmware+14 | 8/6/2025 | 17/6/2026 | The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7… | |
| Analizada | Alta (7.8) | 0.61% | — | Onsemi Qcs-ax3-s5 FirmwareOnsemi Qcs-ax2-a12 FirmwareOnsemi Qcs-ax2-t12 FirmwareOnsemi Qcs-ax2-t8 Firmware+14 | 8/6/2025 | 17/6/2026 | The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7… | |
| Analizada | Alta (7.8) | 0.61% | — | Onsemi Qcs-ax3-s5 FirmwareOnsemi Qcs-ax2-a12 FirmwareOnsemi Qcs-ax2-t12 FirmwareOnsemi Qcs-ax2-t8 Firmware+14 | 8/6/2025 | 17/6/2026 | The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7… | |
| Analizada | Alta (7.8) | 0.60% | — | Onsemi Qcs-ax3-s5 FirmwareOnsemi Qcs-ax2-a12 FirmwareOnsemi Qcs-ax2-t12 FirmwareOnsemi Qcs-ax2-t8 Firmware+14 | 8/6/2025 | 17/6/2026 | The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7… | |
| Analizada | Alta (7.8) | 0.60% | — | Onsemi Qcs-ax3-s5 FirmwareOnsemi Qcs-ax2-a12 FirmwareOnsemi Qcs-ax2-t12 FirmwareOnsemi Qcs-ax2-t8 Firmware+14 | 8/6/2025 | 17/6/2026 | The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a CVSS 7.7… |