Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Commscope Arris Surfboard Sbg6950ac2 Firmware26/1/202417/6/2026
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.
ModificadaAlta (8.8)0.68%—Commscope Arris Surfboard Sbg6950ac2 FirmwareCommscope Arris Surfboard Sbg7400ac2 FirmwareCommscope Arris Surfboard Sbg7580ac FirmwareCommscope Arris Surfboard Sbg7600ac2 Firmware+115/2/202217/6/2026
CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.
ModificadaAlta (7.1)0.46%—Commscope Arris Surfboard Sb8200 Firmware9/11/202117/6/2026
The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.
ModificadaAlta (8.8)0.56%—Commscope Arris Surfboard Sb8200 Firmware21/10/202117/6/2026
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.
ModificadaMedia (5)8.6%—Motorola Surfboard Sbv6120e16/6/201016/6/2026
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.
ModificadaAlta (7.8)1.5%—Motorola Surfboard28/4/200816/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html, and (2) cause a denial of service (hard…
ModificadaAlta (7.8)7.8%—Motorola Surfboard10/10/200616/6/2026
The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.
ModificadaMedia (5)1.7%—Motorola Surfboard31/12/200216/6/2026
Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.