Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.1% | — | Trendnet Tew-632brp Firmware | 27/1/2025 | 17/6/2026 | TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request. | |
| Modificada | Alta (8.8) | 5.0% | — | Dlink Dir-825 FirmwareTrendnet Tew-632brp Firmware | 7/3/2020 | 17/6/2026 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected. | |
| Modificada | Alta (8.8) | 5.3% | — | Dlink Dir-825 FirmwareTrendnet Tew-632brp Firmware | 7/3/2020 | 17/6/2026 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected. | |
| Modificada | Alta (8.8) | 5.0% | — | Dlink Dir-825 FirmwareTrendnet Tew-632brp Firmware | 7/3/2020 | 17/6/2026 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin parameter in a set_sta_enrollee_pin.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected. | |
| Modificada | Crítica (9.8) | 1.5% | — | Trendnet Tew-632brp Firmware | 22/4/2019 | 17/6/2026 | apply.cgi on the TRENDnet TEW-632BRP 1.010B32 router has a buffer overflow via long strings to the SOAPACTION:HNAP1 interface. | |
| Modificada | Alta (8.8) | 2.9% | — | Trendnet Tew-632brp FirmwareTrendnet Tew-673gru Firmware | 20/12/2018 | 17/6/2026 | Buffer overflow in apply.cgi on TRENDnet TEW-632BRP 1.010B32 and TEW-673GRU devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (with authentication). |