Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.56%—Realtek Rtl8192cdAIRealtek Rtl819xAI5/5/20265/7/2026
The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks on the write_mem (ioctl 0x89F5) and read_mem (ioctl 0x89F6) debug handlers, which are compiled into production builds via the unconditionally defined _IOCTL_DEBUG_CMD_…
ModificadaAlta (7.2)0.94%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead to arbitrary code execution. An attacker can upload a malicious file to trigger this vulnerability.
ModificadaAlta (7.2)1.9%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related…
ModificadaAlta (7.2)1.9%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related…
ModificadaAlta (7.2)3.2%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related…
ModificadaAlta (7.2)1.1%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.
ModificadaAlta (7.2)1.4%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow…
ModificadaAlta (7.2)1.4%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow…
ModificadaAlta (7.2)1.4%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This stack-based…
ModificadaAlta (7.2)1.4%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This stack-based…
ModificadaAlta (7.2)1.1%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.
ModificadaAlta (7.2)0.89%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (7.2)0.89%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (7.2)0.89%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (7.2)1.4%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (8.8)0.36%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.2)1.2%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (7.2)1.0%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (7.2)1.3%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.2)0.47%—Realtek Rtl819x Jungle Software Development KITLevel1 Wbr-6013 Firmware8/7/202417/6/2026
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary firmware update. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (8.8)1.3%—Realtek Rtl819x Software Development KIT28/7/202217/6/2026
Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.
AnalizadaCrítica (9.8)98%⚠ Explotación activaRealtek Rtl819x Jungle Software Development KIT16/8/202117/6/2026
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these…
AnalizadaCrítica (9.8)100%⚠ Explotación activaRealtek Rtl819x Jungle Software Development KIT16/8/202117/6/2026
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
AnalizadaCrítica (9.8)70%—Realtek Rtl819x Jungle Software Development KIT16/8/202117/6/2026
Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a stack buffer overflow vulnerability that is present due to unsafe parsing of…
AnalizadaAlta (7.5)83%—Realtek Rtl819x Jungle Software Development KIT16/8/202117/6/2026
Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a heap buffer overflow that is present due to unsafe crafting of SSDP NOTIFY…