Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 1.8% | 💥 PoC | Tp-link Tl-wr802n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware | 16/3/2026 | 1/7/2026 | A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in… | |
| Analizada | Media (6.5) | 16% | ⚠ Explotación activa | Tp-link Tl-wr841n FirmwareTp-link Mr6400 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+32 | 3/5/2024 | 3/9/2026 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (8.8) | 0.91% | — | Tp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware | 3/5/2024 | 17/6/2026 | TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Media (6.8) | 0.42% | — | Tp-link Tl-wr840n Firmware | 25/5/2022 | 17/6/2026 | TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root user without authentication. | |
| Modificada | Alta (7.2) | 1.6% | — | Tp-link Tl-wr840n Firmware | 18/4/2022 | 17/6/2026 | Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature. | |
| Modificada | Alta (7.2) | 1.3% | — | Tp-link Tl-wr840n Firmware | 28/3/2022 | 17/6/2026 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter. | |
| Modificada | Alta (7.2) | 1.3% | — | Tp-link Tl-wr840n Firmware | 28/3/2022 | 17/6/2026 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter. | |
| Modificada | Alta (7.2) | 1.3% | — | Tp-link Tl-wr840n Firmware | 28/3/2022 | 17/6/2026 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter. | |
| Modificada | Alta (7.2) | 1.3% | — | Tp-link Tl-wr840n Firmware | 28/3/2022 | 17/6/2026 | TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter. | |
| Modificada | Crítica (9.8) | 36% | 💥 PoC | Tp-link Tl-wr840n Firmware | 25/2/2022 | 9/7/2026 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr. | |
| Modificada | Alta (7.5) | 3.5% | 💥 PoC | Tp-link Tl-wr840n Firmware | 25/2/2022 | 9/7/2026 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Tp-link Tl-wr840n Firmware | 25/2/2022 | 9/7/2026 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute. | |
| Modificada | Crítica (9.8) | 40% | 💥 PoC | Tp-link Tl-wr840n Firmware | 25/2/2022 | 9/7/2026 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. | |
| Modificada | Crítica (9.8) | 76% | 💥 Exploit | Tp-link Tl-wr840n Firmware | 13/11/2021 | 9/7/2026 | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field. | |
| Modificada | Media (6.4) | 0.75% | — | Tp-link Tl-wr840n Firmware | 19/8/2021 | 17/6/2026 | In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow | |
| Modificada | Crítica (9.8) | 9.8% | — | Tp-link Tl-wr840n Firmware | 6/1/2021 | 17/6/2026 | oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function… | |
| Modificada | Alta (8.8) | 4.0% | — | Tp-link Tl-wr840n Firmware | 22/8/2019 | 17/6/2026 | The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field. | |
| Modificada | Media (4.8) | 1.8% | 💥 Exploit | Tp-link Tl-wr840n Firmware | 24/5/2019 | 17/6/2026 | TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the… | |
| Modificada | Alta (7.5) | 1.9% | — | Tp-link Tl-wr840n Firmware | 29/3/2019 | 17/6/2026 | TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command. | |
| Modificada | Alta (7.5) | 8.3% | 💥 Exploit | Tp-link Tl-wr840n Firmware | 15/8/2018 | 17/6/2026 | TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header. | |
| Modificada | Crítica (9.8) | 68% | 💥 PoC | Tp-link Tl-wr840n FirmwareTp-link Tl-wr841n Firmware | 4/6/2018 | 17/6/2026 | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer:… | |
| Modificada | Media (6.8) | 0.98% | — | Tp-link Tl-wr840n Firmware | 9/1/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firmware before 3.13.27 build 141120 allows remote attackers to hijack the authentication of administrators for requests that change router settings via a configuration file import. |