Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 300 respecto a la semana anterior
Críticas / altas1352▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8)0.34%—Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 2105 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie Firmware+337/5/202617/6/2026
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.
AplazadaMedia (6.6)0.90%—Panasonic Ud-lt2 FirmwareAI22/1/202517/6/2026
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected product, an arbitrary OS command may be executed.
AnalizadaAlta (8.8)0.76%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
ModificadaMedia (5.7)0.41%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which…
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+2610/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.
ModificadaAlta (8.8)0.56%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
AnalizadaAlta (8.8)0.56%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.
AnalizadaAlta (8.8)0.74%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.
AnalizadaAlta (8.8)0.74%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
AnalizadaMedia (5.3)0.48%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.
ModificadaAlta (8.8)0.25%—Elecom Wrc-1167gs2-b FirmwareElecom Wrc-1167gs2h-b FirmwareElecom Wrc-1167gst2 FirmwareElecom Wrc-2533gs2-b Firmware+728/2/202417/6/2026
Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product. Note that WMC-X1800GST-B and WSC-X1800GS-B are also included in…
AnalizadaMedia (4.8)1.3%—Elecom Wrc-1167gs2-b FirmwareElecom Wrc-1167gs2h-b FirmwareElecom Wrc-1167gst2 FirmwareElecom Wrc-2533gs2-b Firmware+628/2/202417/6/2026
ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Note that…
ModificadaAlta (7.8)0.35%—Kramerav VIA GO2 FirmwareKramerav VIA Connect2 Firmware9/8/20239/7/2026
In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.
ModificadaCrítica (9.1)0.76%—Kramerav VIA GO2 FirmwareKramerav VIA Connect2 Firmware9/8/20239/7/2026
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.
ModificadaMedia (6.5)0.32%—Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+13/7/202317/6/2026
​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The attacker could then obtain the plaintext…
ModificadaMedia (6.5)0.51%—Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+13/7/202317/6/2026
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher privileges by establishing an SSH session and providing the other tokens.
ModificadaMedia (5.9)0.51%—Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+13/7/202317/6/2026
​The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the token are generated using predictable time-based values. An attacker with this knowledge could successfully brute force the…
ModificadaAlta (7.2)0.70%—Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+13/7/202317/6/2026
The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges.
ModificadaMedia (6.5)0.23%—Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+13/7/202317/6/2026
The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm.
ModificadaMedia (5.3)0.49%—Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+129/6/202317/6/2026
The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information such as software versions and web server file contents.
ModificadaMedia (5.3)0.62%—Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie FirmwarePhoenixcontact FL Mguard 4302 Firmware+2213/6/202317/6/2026
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.