Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Tenda W6 Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been rated as critical. Affected by this issue is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit… | |
| Modificada | Crítica (9.8) | 1.7% | — | Tenda W6 Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been declared as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 0.62% | — | Proscend M357-5g FirmwareProscend M357-ai FirmwareProscend M350-5g FirmwareProscend M350-w5g Firmware+16 | 3/9/2023 | 17/6/2026 | Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials | |
| Modificada | Media (6.5) | 0.31% | — | Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+116 | 11/4/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the… | |
| Modificada | Media (4.8) | 0.50% | — | Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+46 | 11/4/2023 | 17/6/2026 | Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network… | |
| Modificada | Crítica (9.8) | 2.9% | — | Proscend M330-w FirmwareProscend M330-w5 FirmwareProscend M350-5g FirmwareProscend M350-w5g Firmware+5 | 13/9/2022 | 17/6/2026 | PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W6 / M301-G / M301-GW ADVICE ICR 111WG / https://www.proscend.com/en/category/industrial-Cellular-Router/industrial-Cellular-Router.html… | |
| Modificada | Alta (7.5) | 1.0% | — | Tenda W6 Firmware | 12/8/2022 | 17/6/2026 | A stack overflow vulnerability exists in /goform/WifiMacFilterSet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Tenda W6 Firmware | 12/8/2022 | 17/6/2026 | A stack overflow vulnerability exists in /goform/wifiSSIDset in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter. | |
| Modificada | Crítica (9.8) | 12% | — | Tenda W6 Firmware | 12/8/2022 | 17/6/2026 | A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and ping2 parameters for a stack overflow attack. An attacker can use this vulnerability to execute arbitrary code execution. | |
| Modificada | Alta (7.5) | 1.0% | — | Tenda W6 Firmware | 12/8/2022 | 17/6/2026 | A stack overflow vulnerability exists in /goform/WifiMacFilterGet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Tenda W6 Firmware | 12/8/2022 | 17/6/2026 | A stack overflow vulnerability exists in /goform/wifiSSIDget in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter. | |
| Modificada | Crítica (9.8) | 26% | — | Tenda W6 Firmware | 12/8/2022 | 17/6/2026 | A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution. | |
| Modificada | Alta (8.8) | 1.5% | — | Martem Telem-gw6 FirmwareMartem Telem-gwm Firmware | 1/10/2018 | 17/6/2026 | Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using default credentials to connect to the RTU. | |
| Modificada | Media (6.1) | 2.3% | — | Martem Telem-gwm FirmwareMartem Telem-gw6 Firmware | 31/7/2018 | 17/6/2026 | Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow improper sanitization of data over a Websocket which may allow cross-site scripting and client-side code execution with target user privileges. | |
| Modificada | Alta (7.5) | 3.2% | — | Martem Telem-gwm FirmwareMartem Telem-gw6 Firmware | 31/7/2018 | 17/6/2026 | Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more IOAs, without closing them properly, which may cause a denial of service within the industrial process control channel. | |
| Modificada | Crítica (9.8) | 3.3% | — | Martem Telem-gwm FirmwareMartem Telem-gw6 Firmware | 31/7/2018 | 17/6/2026 | Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the industrial process. | |
| Modificada | Alta (8.1) | 3.7% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology is absolute path traversal in cgi-bin/MANGA/firmware_process.cgi via the upfile.path parameter. | |
| Modificada | Media (5.3) | 3.6% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted… | |
| Modificada | Media (6.1) | 1.8% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/preview.cgi. | |
| Modificada | Media (6.1) | 1.8% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/HASync/hasync.cgi. | |
| Modificada | Crítica (9.8) | 4.9% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to… | |
| Modificada | Alta (8.8) | 1.9% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute commands, if a logged in user visits a malicious website. This… | |
| Modificada | Crítica (9.8) | 62% | — | Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+2 | 5/6/2017 | 17/6/2026 | SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be… |