Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.7)0.64%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml.
ModificadaMedia (5.7)0.64%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing Tftpd32.ini.
ModificadaMedia (6.3)0.63%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configure device settings via accessing the page mb_wifibasic.shtml.
ModificadaMedia (5.7)0.64%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via accessing the page tftp.txt.
ModificadaAlta (8)0.87%—Wavlink Wifi-repeater Firmware25/7/202217/6/2026
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system key information and execute arbitrary commands via accessing the page syslog.shtml.
ModificadaAlta (7.5)4.2%💥 ExploitAcexy Wireless-n Wifi Repeater Firmware29/3/20219/7/2026
The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP.
ModificadaAlta (7.5)2.0%—Acexy Wireless-n Wifi Repeater Firmware29/3/20219/7/2026
The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous authentication is required.
ModificadaMedia (6.1)0.82%—Acexy Wireless-n Wifi Repeater Project Acexy Wireless-n Wifi Repeater Firmware18/3/202117/6/2026
Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is displayed in the /repeater.html page ("Repeater Wizard" homepage section).
ModificadaCrítica (9.8)1.4%—Twsz Wifi Repeater Firmware20/9/201717/6/2026
On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root") and can: 1. Read the entire file system; 2. Write to the file system; or 3. Execute any code that attacker desires (malicious or not).
ModificadaCrítica (9.8)1.4%—Twsz Wifi Repeater Firmware20/9/201717/6/2026
On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root"). The attacker can make a user that is connected to the repeater click on a malicious link that will log into the telnet and will infect the device with…
ModificadaAlta (7.5)10%💥 ExploitTwsz Wifi Repeater Firmware20/9/201717/6/2026
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a crafted getpage parameter.
ModificadaAlta (8.8)9.1%💥 ExploitTwsz Wifi Repeater Firmware7/9/201717/6/2026
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user parameter to cgi-bin/webupg.