Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.72% | — | Mitsubishielectric SmartrtuAI | 21/8/2025 | 17/6/2026 | A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete information in Mitsubishi Electric smartRTU, or cause a denial-of service condition on the product. | |
| Modificada | Alta (8.8) | 0.76% | — | Phoenixcontact Energy AXC PUPhoenixcontact Infobox FirmwarePhoenixcontact Smartrtu AXC SG FirmwarePhoenixcontact Smartrtu AXC IG Firmware | 17/4/2023 | 17/6/2026 | In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service. | |
| Modificada | Media (6.1) | 4.0% | — | Mitsubishielectric Smartrtu Firmware | 15/10/2021 | 17/6/2026 | Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php. | |
| Modificada | Alta (7.5) | 20% | — | Mitsubishielectric Smartrtu Firmware | 15/10/2021 | 17/6/2026 | Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI. | |
| Modificada | Crítica (9.8) | 58% | — | Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware | 28/10/2019 | 17/6/2026 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell.… | |
| Modificada | Crítica (9.8) | 2.3% | — | Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware | 28/10/2019 | 17/6/2026 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the accounts ineaadmin and mitsadmin are… | |
| Modificada | Crítica (9.8) | 1.9% | — | Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware | 28/10/2019 | 17/6/2026 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An… | |
| Modificada | Media (5.4) | 44% | — | Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware | 28/10/2019 | 17/6/2026 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is… | |
| Modificada | Alta (7.5) | 42% | — | Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware | 28/10/2019 | 17/6/2026 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other… | |
| Modificada | Crítica (9.8) | 2.1% | — | Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware | 28/10/2019 | 17/6/2026 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being regenerated on initial installation or with firmware updates. In… | |
| Modificada | Media (6.5) | 1.3% | — | Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware | 28/10/2019 | 17/6/2026 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other… |