Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.2)0.36%—Netgear Rax30 FirmwareNetgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware+18/9/202611/9/2026
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the…
AnalizadaMedia (4.6)0.14%—Netgear Rax120 FirmwareNetgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware9/6/202623/7/2026
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
AnalizadaAlta (8.8)0.88%—Netgear Rax30 FirmwareNetgear Raxe300 FirmwareNetgear Rax40 FirmwareNetgear Rax35 Firmware+13/5/202417/6/2026
NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of…
ModificadaAlta (8)1.5%—Netgear Cax80 FirmwareNetgear Lax20 FirmwareNetgear Mr60 FirmwareNetgear Mr80 Firmware+2929/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling…
ModificadaAlta (8.8)1.3%—Netgear Lax20 FirmwareNetgear R6400 FirmwareNetgear R6700 FirmwareNetgear R7000 Firmware+1929/3/202317/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing…
ModificadaAlta (8.8)0.88%—Netgear Cax80 FirmwareNetgear Lax20 FirmwareNetgear Mr60 FirmwareNetgear Mr80 Firmware+2929/3/202317/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service. The issue results from incorrect string matching logic…
ModificadaAlta (7.5)0.77%—Netgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware26/12/202117/6/2026
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.
ModificadaAlta (7.1)1.6%—Netgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware9/12/20219/7/2026
A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.
ModificadaAlta (7.5)1.0%—Netgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware11/8/202117/6/2026
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX35 before 1.0.3.94, RAX38 before 1.0.3.94, and RAX40 before 1.0.3.94.