Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.89% | — | Govicture Rx1800 Firmware | 9/5/2025 | 17/6/2026 | Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability. | |
| Analizada | Alta (8.8) | 0.56% | — | Govicture Rx1800 Firmware | 9/5/2025 | 17/6/2026 | Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication. | |
| Analizada | Media (6.8) | 0.44% | — | Govicture Rx1800 Firmware | 9/5/2025 | 17/6/2026 | An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access. | |
| Modificada | Crítica (9.8) | 0.65% | — | Govicture Rx1800 Firmware | 9/5/2025 | 5/7/2026 | Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address. | |
| Aplazada | Alta (8.8) | 0.46% | — | Victure Rx1800AI | 2/12/2024 | 17/6/2026 | An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default with admin/admin as default credentials and is exposed over the LAN. The allows attackers to execute arbitrary commands with root-level permissions. Device setup does… | |
| Aplazada | Alta (8.8) | 0.56% | — | Victure Rx1800AI | 2/12/2024 | 17/6/2026 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default Wi-Fi PSK value via the last 4 octets of the BSSID. | |
| Aplazada | Alta (8.8) | 2.2% | — | Victure Rx1800AI | 2/12/2024 | 17/6/2026 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /cgi-bin/luci/admin endpoints are vulnerable to command injection. Attackers can exploit this by sending crafted payloads through parameters intended for the ping utility, enabling arbitrary command… | |
| Aplazada | Alta (8.8) | 2.9% | — | Victure Rx1800AI | 2/12/2024 | 17/6/2026 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device… | |
| Aplazada | Alta (8.8) | 0.47% | — | Victure Rx1800AI | 2/12/2024 | 17/6/2026 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default and exposed over the LAN. The root account is accessible without a password, allowing attackers to achieve full control over the router remotely without any… |