Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.85% | — | Trendnet Tew-632brpAI | 16/3/2026 | 17/6/2026 | A vulnerability was detected in TRENDnet TEW-632BRP 1.010B32. This affects an unknown part of the file /ping_response.cgi of the component HTTP POST Request Handler. The manipulation of the argument ping_ipaddr results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public… | |
| Analizada | Crítica (9.8) | 1.1% | — | Trendnet Tew-632brp Firmware | 27/1/2025 | 17/6/2026 | TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request. | |
| Modificada | Alta (8.8) | 5.0% | — | Dlink Dir-825 FirmwareTrendnet Tew-632brp Firmware | 7/3/2020 | 17/6/2026 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected. | |
| Modificada | Alta (8.8) | 5.3% | — | Dlink Dir-825 FirmwareTrendnet Tew-632brp Firmware | 7/3/2020 | 17/6/2026 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected. | |
| Modificada | Alta (8.8) | 5.0% | — | Dlink Dir-825 FirmwareTrendnet Tew-632brp Firmware | 7/3/2020 | 17/6/2026 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin parameter in a set_sta_enrollee_pin.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected. | |
| Modificada | Crítica (9.8) | 1.5% | — | Trendnet Tew-632brp Firmware | 22/4/2019 | 17/6/2026 | apply.cgi on the TRENDnet TEW-632BRP 1.010B32 router has a buffer overflow via long strings to the SOAPACTION:HNAP1 interface. | |
| Modificada | Alta (8.8) | 2.9% | — | Trendnet Tew-632brp FirmwareTrendnet Tew-673gru Firmware | 20/12/2018 | 17/6/2026 | Buffer overflow in apply.cgi on TRENDnet TEW-632BRP 1.010B32 and TEW-673GRU devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (with authentication). |