Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+428/7/202217/6/2026
An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution.
ModificadaCrítica (9.8)0.89%—Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+428/7/202217/6/2026
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
ModificadaCrítica (9.8)1.4%—Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+428/7/202217/6/2026
The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.
ModificadaCrítica (9.8)0.81%—Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+428/7/202217/6/2026
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
ModificadaAlta (7.5)0.85%—Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+428/7/202217/6/2026
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
ModificadaCrítica (9.8)0.81%—Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+428/7/202217/6/2026
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.