Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 80% | — | T-mobile Tm-ac1900Asus WRT Firmware | 8/1/2015 | 17/6/2026 | common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass authentication and execute arbitrary commands via a NET_CMD_ID_MANU_CMD… | |
| Modificada | Alta (7.1) | 1.1% | — | T-mobile Tm-ac1900Asus RT Series Firmware | 4/11/2014 | 17/6/2026 | ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary… | |
| Modificada | Media (4.3) | 1.2% | — | T-mobile Tm-ac1900Asus Rt-ac68u FirmwareAsus Rt-ac68u | 22/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter to apply.cgi. | |
| Modificada | Media (6.3) | 1.1% | — | Asus Rt-ac66u FirmwareAsus Rt-ac68u FirmwareAsus Rt-n10e FirmwareAsus Rt-n14u Firmware+6 | 22/4/2014 | 17/6/2026 | Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remote authenticated users to obtain the administrator user name and password by reading the source code. | |
| Modificada | Alta (8.5) | 9.5% | — | T-mobile Tm-ac1900Asus Rt-ac68u FirmwareAsus Rt-ac68u | 22/4/2014 | 16/6/2026 | The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the Target field (destIP parameter). | |
| Modificada | Alta (10) | 7.8% | — | Asus Tm-ac1900 FirmwareAsus Rt-n56u FirmwareAsus Rt-ac66u Firmware | 22/1/2014 | 17/6/2026 | Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp. | |
| Modificada | Alta (7.2) | 0.62% | — | Redhat Enterprise LinuxT-mobile Tm-ac1900Busybox | 23/11/2013 | 16/6/2026 | util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors. | |
| Modificada | Media (6.8) | 1.8% | — | T-mobile Tm-ac1900Busybox | 3/7/2012 | 16/6/2026 | The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options. |