Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 1.0% | — | Tenda W3 Firmware | 12/3/2026 | 17/6/2026 | A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of the file /goform/wifiSSIDset of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda W3 Firmware | 12/3/2026 | 17/6/2026 | A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda W3 Firmware | 12/3/2026 | 17/6/2026 | A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotely.… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda W3 Firmware | 12/3/2026 | 17/6/2026 | A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component POST Parameter Handler. Performing a manipulation of the argument wl_radio results in stack-based buffer overflow. It is possible to initiate the… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda W3 Firmware | 12/3/2026 | 17/6/2026 | A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the file /goform/exeCommand of the component HTTP Handler. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda W3 Firmware | 12/3/2026 | 17/6/2026 | A vulnerability was determined in Tenda W3 1.0.0.3(2204). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component POST Parameter Handler. This manipulation of the argument ping1/ping2 causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.74% | — | Tenda W3 Firmware | 12/3/2026 | 17/6/2026 | A vulnerability was found in Tenda W3 1.0.0.3(2204). Affected by this issue is the function formSetCfm of the file /goform/setcfm of the component HTTP Handler. The manipulation of the argument funcpara1 results in stack-based buffer overflow. The attack can only be performed from the local network. The exploit has… | |
| Modificada | Media (6.5) | 0.31% | — | Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+116 | 11/4/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the… | |
| Modificada | Media (4.8) | 0.50% | — | Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+46 | 11/4/2023 | 17/6/2026 | Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network… | |
| Modificada | Crítica (9.8) | 7.0% | — | Crestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+8 | 30/4/2019 | 17/6/2026 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Crestron Am-100 FirmwareCrestron Am-101 FirmwareBarco Wepresent Wipg-1000p FirmwareBarco Wepresent Wipg-1600w Firmware+8 | 30/4/2019 | 17/6/2026 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5,… | |
| Modificada | Media (6.7) | 0.42% | — | Supermicro X11ssz FirmwareSupermicro X11ssv FirmwareSupermicro X11ssql FirmwareSupermicro X11ssq Firmware+106 | 9/7/2018 | 17/6/2026 | Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware. | |
| Modificada | Alta (8.1) | 3.7% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology is absolute path traversal in cgi-bin/MANGA/firmware_process.cgi via the upfile.path parameter. | |
| Modificada | Media (5.3) | 3.6% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted… | |
| Modificada | Media (6.1) | 1.8% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/preview.cgi. | |
| Modificada | Media (6.1) | 1.8% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/HASync/hasync.cgi. | |
| Modificada | Crítica (9.8) | 4.9% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to… | |
| Modificada | Alta (8.8) | 1.9% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute commands, if a logged in user visits a malicious website. This… | |
| Modificada | Crítica (9.8) | 62% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be… |