Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.57% | — | Tp-link Wdr201aAI | 4/5/2026 | 17/6/2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firewall.cgi and makeRequest.cgi binaries that allows unauthenticated attackers to overwrite the saved return address by sending a POST request with a Content-Length header exceeding 512 bytes. Attackers… | |
| Aplazada | Crítica (9.3) | 1.9% | — | Tp-link Wdr201aAI | 4/5/2026 | 17/6/2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across five request handlers that apply insufficient input validation. Attackers can inject arbitrary shell commands through vulnerable parameters like websURLFilter, websHostFilter,… | |
| Aplazada | Crítica (9.3) | 4.1% | — | Tp-link Wdr201aAI | 4/5/2026 | 17/6/2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the reboot_time POST parameter. Attackers can send a… | |
| Aplazada | Crítica (9.3) | 3.3% | — | Tp-link Wdr201aAI | 4/5/2026 | 17/6/2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the set_time or StartSniffer functions. Attackers can craft a POST… | |
| Aplazada | Crítica (9.3) | 3.2% | — | Dlink Wdr201aAI | 4/5/2026 | 17/6/2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the gateway POST parameter. Attackers can exploit unsanitized parameter… | |
| Aplazada | Crítica (9.3) | 6.7% | — | Dlink Wdr201aAI | 4/5/2026 | 17/6/2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the sz11gChannel or PIN POST parameters. Attackers can exploit unsanitized… | |
| Pendiente de análisis | Crítica (9.1) | 0.54% | — | Wdr201aAI | 18/3/2026 | 17/6/2026 | The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB | |
| Pendiente de análisis | Crítica (9.8) | 2.0% | — | Tp-link Wdr201aAI | 18/3/2026 | 17/6/2026 | A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi endpoint improperly sanitizes user-supplied input provided to a command-related parameter in the sysCMD functionality. | |
| Pendiente de análisis | Crítica (9.8) | 0.69% | — | Wdr201aAI | 18/3/2026 | 17/6/2026 | The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints through forced… | |
| Pendiente de análisis | Crítica (9.1) | 0.67% | — | Tp-link Wdr201aAI | 18/3/2026 | 17/6/2026 | The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side web pages, including login.shtml and settings.shtml. These pages embed server-side execution directives that dynamically… |