Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN RoutersAIElecom Access PointsAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN RoutersAIElecom Wireless LAN Access PointsAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Pendiente de análisisMedia (6.9)0.30%—Sharp RoutersAI25/3/202617/6/2026
SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.
AplazadaCrítica (9.3)1.6%—Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance Managed RoutersAI27/1/202617/6/2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router: This issue affects Session Smart Conductor: This issue…
AplazadaCrítica (9.9)14%—Zoom Node Multimedia RoutersAI20/1/202617/6/2026
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.
AplazadaCrítica (9.9)0.60%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby…
AplazadaCrítica (9.3)0.52%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In…
AplazadaMedia (5.3)0.58%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping` function, which is restricted to higher-privileged…
AplazadaCrítica (9.3)0.66%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in broken access control has been identified in the /api/v1/setting/data endpoint of the affected device. This flaw allows a low-privileged authenticated user to call the API without the…
AplazadaAlta (8.7)0.51%—Moxa Network Security AppliancesAIMoxa RoutersAI17/10/202517/6/2026
An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploited after a legitimate…
AplazadaCrítica (10)93%—Linksys E-series RoutersAILinksys WAG Series RoutersAILinksys WAP Series RoutersAILinksys WES Series RoutersAI+224/6/202522/7/2026
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to…
AplazadaCrítica (9.3)1.8%—Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI3/1/202517/6/2026
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s…
AplazadaAlta (8.6)1.2%—Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI3/1/202517/6/2026
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.
AplazadaAlta (8.8)6.3%—Dlink Wireless RoutersAI17/6/202417/6/2026
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
ModificadaMedia (4.7)2.1%—Routers2 Project Routers224/1/201817/6/2026
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to cgi-bin/routers2.pl.
ModificadaMedia (5)1.3%—Cisco Broadband Operating SystemCisco 6XX Routers16/2/200116/6/2026
CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.
ModificadaMedia (5)1.7%—Cisco Broadband Operating SystemCisco 6XX Routers16/2/200116/6/2026
The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.
ModificadaMedia (5)1.3%—Cisco Broadband Operating SystemCisco 6XX Routers16/2/200116/6/2026
Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.
ModificadaBaja (3.6)1.8%—Netopia R-series Routers16/5/200016/6/2026
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.
ModificadaMedia (5)3.4%—Cisco 7XX Routers11/3/199916/6/2026
Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.
ModificadaAlta (7.5)1.4%—Cisco 7XX Routers11/3/199916/6/2026
The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.
ModificadaMedia (5)1.4%—Lucent Ascend Routers1/3/199916/6/2026
Denial of service of Ascend routers through port 150 (remote administration).
ModificadaAlta (7.5)1.4%—Ascom Timeplex Routers15/5/199716/6/2026
Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.