Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)1.0%—Trendnet Tew-821dapAI22/8/202626/8/2026
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument…
AplazadaBaja (2.1)1.8%—Trendnet Tew-821dapAI22/8/202625/8/2026
A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)1.8%—Trendnet Tew-821dapAI19/8/202621/8/2026
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-bin/ping.cgi of the component ssi. Executing a manipulation of the argument ipaddr can lead to command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed…
AplazadaMedia (5.3)1.8%—Trendnet Tew-821dapAI12/7/202613/7/2026
A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. Performing a manipulation of the argument Hostname results in os command injection. The attack may be initiated remotely. The vendor explains: "We are…
AplazadaMedia (5.3)1.8%—Trendnet Tew-821dapAI12/7/202613/7/2026
A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. Such manipulation of the argument hostname/username/password leads to os command injection. The attack can be launched remotely. The vendor…
AplazadaMedia (5.3)1.8%—Trendnet Tew-821dapAI12/7/202614/7/2026
A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. This manipulation of the argument nslookup_target/dns_server causes os command injection. The attack can be initiated remotely. The vendor…
AplazadaAlta (8.7)0.79%—Trendnet Tew-821dapAI12/7/202613/7/2026
A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. The affected element is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation results in buffer overflow. It is possible to launch the attack remotely. The vendor explains: "We are unable to confirm the existence…
AplazadaAlta (8.7)0.79%—Trendnet Tew-821dapAI12/7/202615/7/2026
A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function sub_41EC14 of the file /goform/tools_nslookup of the component ssi. The manipulation of the argument nslookup_target leads to buffer overflow. It is possible to initiate the attack remotely. The vendor explains: "We are…
AnalizadaMedia (6.3)0.31%—Trendnet Tew-821dap Firmware2/5/202617/6/2026
A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev of the file cameo_dev.sh of the component Firmware Update Handler. Performing a manipulation results in insufficient verification of data authenticity. The attack is possible to be carried out…
AnalizadaBaja (2.9)0.45%—Trendnet Tew-821dap Firmware2/5/202617/6/2026
A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi of the component Firmware Update. Such manipulation leads to cleartext transmission of sensitive information. The attack can be executed remotely. This attack is characterized by high complexity.…
AnalizadaBaja (2.1)5.7%—Trendnet Tew-821dap Firmware2/5/202617/6/2026
A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the component Firmware Udpate. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.…
AnalizadaBaja (2)9.8%—Trendnet Tew-821dap Firmware2/5/202617/6/2026
A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injection. The exploit is now public and may be used. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have…
AnalizadaAlta (8.7)1.0%—Trendnet Tew-821dap Firmware2/5/202617/6/2026
A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware of the component Firmware Udpate. The manipulation of the argument str leads to buffer overflow. The attack may be initiated remotely. The vendor explains: "That firmware version will only work on…
AnalizadaMedia (6.3)0.31%—Trendnet Tew-821dap Firmware2/5/202617/6/2026
A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_firmware of the component Firmware Update Handler. Executing a manipulation of the argument dest can lead to insufficient verification of data authenticity. The attack can be launched remotely.…
AnalizadaAlta (8)0.50%—Trendnet Tew-821dap Firmware26/3/202417/6/2026
Buffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_mod_pwd action.
AnalizadaAlta (8)0.50%—Trendnet Tew-821dap Firmware26/3/202417/6/2026
Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.
ModificadaAlta (8)0.53%—Trendnet Tew-821dap Firmware26/3/20249/7/2026
An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.
ModificadaMedia (6.5)0.81%—Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware10/8/202117/6/2026
A Format String vulnerablity exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service due to a logic bug at address 0x40dcd0 when calling fprintf with "%s: key len = %d, too long\n" format. The two…
ModificadaAlta (7.5)0.96%—Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware10/8/202117/6/2026
Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending the POST request to apply_cgi via the lang action without a language key.
ModificadaAlta (7.5)0.96%—Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware10/8/202117/6/2026
Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi via a do_graph_auth action without a session_id key.
ModificadaAlta (7.5)0.96%—Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware10/8/202117/6/2026
Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi with an unknown action name.
ModificadaAlta (7.5)0.96%—Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware10/8/202117/6/2026
Null Pointer Deference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial os service by sending the POST request to apply_cgi via action do_graph_auth without login_name key.
ModificadaAlta (7.5)0.96%—Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware10/8/202117/6/2026
Null Pointer Dereference vulnerability in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending a POST request to apply_cgi via an action ping_test without a ping_ipaddr key.
Orbitaley — Vulnerabilidades