Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Tenda W6 Firmware29/1/202417/6/2026
A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been rated as critical. Affected by this issue is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit…
ModificadaCrítica (9.8)1.7%—Tenda W6 Firmware29/1/202417/6/2026
A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been declared as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched remotely. The…
ModificadaCrítica (9.8)0.62%—Proscend M357-5g FirmwareProscend M357-ai FirmwareProscend M350-5g FirmwareProscend M350-w5g Firmware+163/9/202317/6/2026
Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials
ModificadaMedia (6.5)0.31%—Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+11611/4/202317/6/2026
Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the…
ModificadaMedia (4.8)0.50%—Epson Lp-9200ps2 FirmwareEpson Lp-9200ps3 FirmwareEpson Lp-8200c FirmwareEpson Lp-9600 Firmware+4611/4/202317/6/2026
Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network…
ModificadaCrítica (9.8)2.9%—Proscend M330-w FirmwareProscend M330-w5 FirmwareProscend M350-5g FirmwareProscend M350-w5g Firmware+513/9/202217/6/2026
PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W6 / M301-G / M301-GW ADVICE ICR 111WG / https://www.proscend.com/en/category/industrial-Cellular-Router/industrial-Cellular-Router.html…
ModificadaAlta (7.5)1.0%—Tenda W6 Firmware12/8/202217/6/2026
A stack overflow vulnerability exists in /goform/WifiMacFilterSet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.
ModificadaAlta (7.5)1.0%—Tenda W6 Firmware12/8/202217/6/2026
A stack overflow vulnerability exists in /goform/wifiSSIDset in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.
ModificadaCrítica (9.8)12%—Tenda W6 Firmware12/8/202217/6/2026
A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and ping2 parameters for a stack overflow attack. An attacker can use this vulnerability to execute arbitrary code execution.
ModificadaAlta (7.5)1.0%—Tenda W6 Firmware12/8/202217/6/2026
A stack overflow vulnerability exists in /goform/WifiMacFilterGet in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.
ModificadaAlta (7.5)1.0%—Tenda W6 Firmware12/8/202217/6/2026
A stack overflow vulnerability exists in /goform/wifiSSIDget in Tenda W6 V1.0.0.9(4122) version, which can be exploited by attackers to cause a denial of service (DoS) via the index parameter.
ModificadaCrítica (9.8)26%—Tenda W6 Firmware12/8/202217/6/2026
A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution.
ModificadaAlta (8.8)1.5%—Martem Telem-gw6 FirmwareMartem Telem-gwm Firmware1/10/201817/6/2026
Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using default credentials to connect to the RTU.
ModificadaMedia (6.1)2.3%—Martem Telem-gwm FirmwareMartem Telem-gw6 Firmware31/7/201817/6/2026
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow improper sanitization of data over a Websocket which may allow cross-site scripting and client-side code execution with target user privileges.
ModificadaAlta (7.5)3.2%—Martem Telem-gwm FirmwareMartem Telem-gw6 Firmware31/7/201817/6/2026
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more IOAs, without closing them properly, which may cause a denial of service within the industrial process control channel.
ModificadaCrítica (9.8)3.3%—Martem Telem-gwm FirmwareMartem Telem-gw6 Firmware31/7/201817/6/2026
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the industrial process.
ModificadaAlta (8.1)3.7%—Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology is absolute path traversal in cgi-bin/MANGA/firmware_process.cgi via the upfile.path parameter.
ModificadaMedia (5.3)3.6%—Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted…
ModificadaMedia (6.1)1.8%—Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/preview.cgi.
ModificadaMedia (6.1)1.8%—Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/HASync/hasync.cgi.
ModificadaCrítica (9.8)4.9%—Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to…
ModificadaAlta (8.8)1.9%—Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute commands, if a logged in user visits a malicious website. This…
ModificadaCrítica (9.8)62%—Peplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be…