Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Alta (8.6) | 1.7% | — | Elecom Wireless LAN RoutersAIElecom Wireless LAN Access PointsAI | 28/7/2026 | 28/7/2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | Sharp RoutersAI | 25/3/2026 | 17/6/2026 | SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over. | |
| Aplazada | Crítica (9.3) | 1.6% | — | Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance Managed RoutersAI | 27/1/2026 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router: This issue affects Session Smart Conductor: This issue… | |
| Aplazada | Crítica (9.9) | 14% | — | Zoom Node Multimedia RoutersAI | 20/1/2026 | 17/6/2026 | A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access. | |
| Aplazada | Crítica (9.9) | 0.60% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded secret key to sign JSON Web Tokens (JWT) used for authentication. This insecure implementation allows an unauthenticated attacker to forge valid tokens, thereby… | |
| Aplazada | Crítica (9.3) | 0.52% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A critical authorization flaw in the API allows an authenticated, low-privileged user to create a new administrator account, including accounts with usernames identical to existing users. In… | |
| Aplazada | Media (5.3) | 0.58% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authorization logic of the affected device allows an authenticated, low-privileged user to execute the administrative `ping` function, which is restricted to higher-privileged… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in broken access control has been identified in the /api/v1/setting/data endpoint of the affected device. This flaw allows a low-privileged authenticated user to call the API without the… | |
| Aplazada | Alta (8.7) | 0.51% | — | Moxa Network Security AppliancesAIMoxa RoutersAI | 17/10/2025 | 17/6/2026 | An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mechanism allows unauthorized access to protected API endpoints, including those intended for administrative functions. This vulnerability can be exploited after a legitimate… | |
| Aplazada | Crítica (10) | 93% | — | Linksys E-series RoutersAILinksys WAG Series RoutersAILinksys WAP Series RoutersAILinksys WES Series RoutersAI+2 | 24/6/2025 | 22/7/2026 | An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to… | |
| Aplazada | Crítica (9.3) | 1.8% | — | Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI | 3/1/2025 | 17/6/2026 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly restricted commands, potentially enabling attackers to execute arbitrary code. This poses a significant risk to the system’s… | |
| Aplazada | Alta (8.6) | 1.2% | — | Moxa Cellular RoutersAIMoxa Secure RoutersAIMoxa Network Security AppliancesAI | 3/1/2025 | 17/6/2026 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk. | |
| Aplazada | Alta (8.8) | 6.3% | — | Dlink Wireless RoutersAI | 17/6/2024 | 17/6/2026 | Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware. | |
| Modificada | Media (4.7) | 2.1% | — | Routers2 Project Routers2 | 24/1/2018 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to cgi-bin/routers2.pl. | |
| Modificada | Media (5) | 1.3% | — | Cisco Broadband Operating SystemCisco 6XX Routers | 16/2/2001 | 16/6/2026 | CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets. | |
| Modificada | Media (5) | 1.7% | — | Cisco Broadband Operating SystemCisco 6XX Routers | 16/2/2001 | 16/6/2026 | The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character. | |
| Modificada | Media (5) | 1.3% | — | Cisco Broadband Operating SystemCisco 6XX Routers | 16/2/2001 | 16/6/2026 | Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet. | |
| Modificada | Baja (3.6) | 1.8% | — | Netopia R-series Routers | 16/5/2000 | 16/6/2026 | The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so. | |
| Modificada | Media (5) | 3.4% | — | Cisco 7XX Routers | 11/3/1999 | 16/6/2026 | Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port. | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco 7XX Routers | 11/3/1999 | 16/6/2026 | The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration. | |
| Modificada | Media (5) | 1.4% | — | Lucent Ascend Routers | 1/3/1999 | 16/6/2026 | Denial of service of Ascend routers through port 150 (remote administration). | |
| Modificada | Alta (7.5) | 1.4% | — | Ascom Timeplex Routers | 15/5/1997 | 16/6/2026 | Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters. |