Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
2 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.2% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+10 | 15/10/2018 | 17/6/2026 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution | |
| Modificada | Crítica (9.8) | 5.4% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+10 | 15/10/2018 | 17/6/2026 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a… |