Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 27/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, how_often, weekdays, monthly_date, and cycle_duration fields into small fixed-size buffers without proper… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 27/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into fixed-size stack buffers without total length checks. A remote attacker can trigger this… | |
| Aplazada | Alta (8.6) | 0.68% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a… | |
| Aplazada | Alta (8.8) | 0.55% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration,… | |
| Aplazada | Media (6.9) | 1.0% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal sequences to access arbitrary files on… | |
| Aplazada | Alta (8.6) | 1.8% | — | Draytek VigorswitchAI | 24/8/2026 | 27/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 27/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands… | |
| Aplazada | Alta (8.7) | 0.69% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a… | |
| Aplazada | Crítica (9.3) | 2.8% | — | Draytek VigorswitchAI | 24/8/2026 | 27/8/2026 | Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary… | |
| Aplazada | Media (6.9) | 0.56% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a crafted request to crash the service and… | |
| Aplazada | Alta (8.6) | 2.3% | — | Draytek VigorswitchAI | 24/8/2026 | 26/8/2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary… |