Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 1.6% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary… | |
| Pendiente de análisis | Crítica (9.4) | 2.9% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command string without proper sanitization. This… | |
| Pendiente de análisis | Alta (8.4) | 0.20% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by… | |
| Pendiente de análisis | Alta (7.1) | 0.37% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical… | |
| Pendiente de análisis | Crítica (9.3) | 1.6% | — | WNC T-mobile 5G BOX IDUAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before… | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | WNC T-mobile 5G BOX IDU RouterAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory… | |
| Aplazada | Alta (7.1) | 0.68% | — | T-mobile G2AI | 22/9/2025 | 17/6/2026 | GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated credentials. However these credentials are not required to access the stream. Changing these values does not change camera's behavior. The vendor did not respond in any way. Only version… | |
| Aplazada | Baja (3.4) | 0.16% | — | BLU View 2AIBoost Mobile Celero 5GAISharp Rouvo VAIMotorola Moto G PureAI+3 | 22/4/2024 | 17/6/2026 | An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers. Various software builds for the BLU View 2, Boost Mobile Celero 5G, Sharp Rouvo V, Motorola Moto G Pure, Motorola Moto G Power, T-Mobile Revvl 6 Pro 5G, and T-Mobile Revvl V+ 5G… | |
| Modificada | Alta (7.5) | 1.8% | — | Coolpad Defiant FirmwareT-mobile Revvl Plus Firmware | 25/4/2019 | 17/6/2026 | The Coolpad Defiant (Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys) and the T-Mobile Revvl Plus (Coolpad/alchemy/alchemy:7.1.1/143.14.171129.3701A-TMO/buildf_nj_02-206:user/release-keys) Android devices contain a pre-installed platform app with a package name of… | |
| Modificada | Crítica (9.8) | 1.9% | — | Coolpad Defiant FirmwareT-mobile Revvl Plus FirmwareT-mobile ZTE Zmax PRO Firmware | 25/4/2019 | 17/6/2026 | The Coolpad Defiant device with a build fingerprint of Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys, the ZTE ZMAX Pro with a build fingerprint of ZTE/P895T20/urd:6.0.1/MMB29M/20170418.114928:user/release-keys, and the T-Mobile Revvl Plus with a build fingerprint of… | |
| Modificada | Alta (7.5) | 1.8% | — | Coolpad Defiant FirmwareT-mobile Revvl Plus FirmwareT-mobile ZTE Zmax PRO Firmware | 25/4/2019 | 17/6/2026 | The Coolpad Defiant device with a build fingerprint of Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys, the ZTE ZMAX Pro with a build fingerprint of ZTE/P895T20/urd:6.0.1/MMB29M/20170418.114928:user/release-keys, and the T-Mobile Revvl Plus with a build fingerprint of… | |
| Modificada | Alta (10) | 80% | — | T-mobile Tm-ac1900Asus WRT Firmware | 8/1/2015 | 17/6/2026 | common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass authentication and execute arbitrary commands via a NET_CMD_ID_MANU_CMD… | |
| Modificada | Alta (7.1) | 1.1% | — | T-mobile Tm-ac1900Asus RT Series Firmware | 4/11/2014 | 17/6/2026 | ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary… | |
| Modificada | Media (5.4) | 0.27% | — | MY T-mobile | 26/9/2014 | 17/6/2026 | The My T-Mobile (aka at.tmobile.android.myt) application @7F0C0030 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.2% | — | T-mobile Tm-ac1900Asus Rt-ac68u FirmwareAsus Rt-ac68u | 22/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter to apply.cgi. | |
| Modificada | Media (6.3) | 1.1% | — | Asus Rt-ac66u FirmwareAsus Rt-ac68u FirmwareAsus Rt-n10e FirmwareAsus Rt-n14u Firmware+6 | 22/4/2014 | 17/6/2026 | Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remote authenticated users to obtain the administrator user name and password by reading the source code. | |
| Modificada | Alta (8.5) | 9.5% | — | T-mobile Tm-ac1900Asus Rt-ac68u FirmwareAsus Rt-ac68u | 22/4/2014 | 16/6/2026 | The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the Target field (destIP parameter). | |
| Modificada | Alta (7.2) | 0.62% | — | Redhat Enterprise LinuxT-mobile Tm-ac1900Busybox | 23/11/2013 | 16/6/2026 | util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors. | |
| Modificada | Alta (7.1) | 1.8% | — | ATT StatusHTC ChachaHTC DesireHTC Merge+5 | 21/8/2012 | 16/6/2026 | The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain… | |
| Modificada | Media (6.8) | 1.8% | — | T-mobile Tm-ac1900Busybox | 3/7/2012 | 16/6/2026 | The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options. | |
| Modificada | Alta (10) | 2.0% | — | T-mobile Voice Mail Systems | 2/4/2007 | 16/6/2026 | T-Mobile voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID). |