Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 2.6% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary… | |
| Aplazada | Alta (8.6) | 1.8% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can trigger this vulnerability via crafted input, causing a denial… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges.… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this vulnerability via crafted input to… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute… | |
| Aplazada | Alta (8.6) | 1.8% | — | Draytek VigorapAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can trigger this vulnerability via crafted input… | |
| Modificada | Crítica (9.8) | 0.59% | — | Draytek MyvigorDraytek Vigorswitch Pq2200xb FirmwareDraytek Vigorswitch Pq2121x FirmwareDraytek Vigorswitch P2540xs Firmware+68 | 1/6/2023 | 17/6/2026 | Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers… | |
| Modificada | Media (5.4) | 0.57% | — | Draytek Vigorap 1000c FirmwareDraytek Vigorap 700 FirmwareDraytek Vigorap 710 FirmwareDraytek Vigorap 800 Firmware+9 | 22/10/2021 | 17/6/2026 | Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username input field. | |
| Modificada | Alta (7.5) | 1.1% | — | Draytek Vigorap 910c Firmware | 15/4/2020 | 17/6/2026 | A vulnerable SNMP in Draytek VigorAP910C cannot be disabled, which may cause information leakage. | |
| Modificada | Media (6.1) | 0.92% | — | Draytek Vigorap 910c Firmware | 7/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to inject arbitrary web script or HTML via vectors involving home.asp. | |
| Modificada | Alta (8.8) | 0.69% | — | Draytek Vigorap 910c Firmware | 7/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack the authentication of unspecified users for requests that enable SNMP on the remote device via vectors involving goform/setSnmp. |