Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.4%—Tp-link Tl-er5510gTp-link Tl-er5520gTp-link Tl-er6120gTp-link Tl-er6520g+5127/11/201717/6/2026
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.
ModificadaMedia (6.5)1.9%—Tp-link Tl-wvr300 FirmwareTp-link Tl-wvr302 FirmwareTp-link Tl-wvr450 FirmwareTp-link Tl-wvr450l Firmware+4927/11/201717/6/2026
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the…
ModificadaAlta (8.8)2.9%—Tp-link Tl-wvr300 FirmwareTp-link Tl-wvr302 FirmwareTp-link Tl-wvr450 FirmwareTp-link Tl-wvr450l Firmware+4927/11/201717/6/2026
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd.
ModificadaAlta (8.8)5.6%—Tp-link Tl-wvr300 FirmwareTp-link Tl-wvr302 FirmwareTp-link Tl-wvr450 FirmwareTp-link Tl-wvr450l Firmware+4927/11/201717/6/2026
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /usr/lib/lua/luci/controller/admin/diagnostic.lua in uhttpd.