Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)1.8%💥 PoCTp-link Tl-wr802n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware16/3/20261/7/2026
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in…
ModificadaAlta (8.8)0.56%—Tp-link Tl-wr902ac FirmwareTp-link Tl-wr802n FirmwareTp-link Tl-wr841n Firmware6/9/202317/6/2026
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to 'TL-WR841N(JP)_V14_230506', and TL-WR902AC firmware versions…
ModificadaAlta (8.8)1.9%—Tp-link Tl-wr802n Firmware23/12/202117/6/2026
TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.
ModificadaAlta (8.1)5.9%—Tp-link Tl-wr802n Firmware12/4/202117/6/2026
TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process in the body message. The attack vector is: The attacker can get shell of the router by sending a message through the network, which may lead to remote code execution.
ModificadaMedia (6.1)1.8%—Tp-link Td-w9977 FirmwareTp-link Tl-wa801nd FirmwareTp-link Tl-wa801n FirmwareTp-link Tl-wr802n Firmware+126/3/202117/6/2026
Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, which affects TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Archer C3150v2 devices through the improper validation of the…
Orbitaley — Vulnerabilidades