Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.7) | 0.64% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml. | |
| Modificada | Media (5.7) | 0.64% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing Tftpd32.ini. | |
| Modificada | Media (6.3) | 0.63% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configure device settings via accessing the page mb_wifibasic.shtml. | |
| Modificada | Media (5.7) | 0.64% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via accessing the page tftp.txt. | |
| Modificada | Alta (8) | 0.87% | — | Wavlink Wifi-repeater Firmware | 25/7/2022 | 17/6/2026 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system key information and execute arbitrary commands via accessing the page syslog.shtml. | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Acexy Wireless-n Wifi Repeater Firmware | 29/3/2021 | 9/7/2026 | The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the administrator account password in plaintext. The page can be intercepted on HTTP. | |
| Modificada | Alta (7.5) | 2.0% | — | Acexy Wireless-n Wifi Repeater Firmware | 29/3/2021 | 9/7/2026 | The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous authentication is required. | |
| Modificada | Media (6.1) | 0.82% | — | Acexy Wireless-n Wifi Repeater Project Acexy Wireless-n Wifi Repeater Firmware | 18/3/2021 | 17/6/2026 | Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is displayed in the /repeater.html page ("Repeater Wizard" homepage section). | |
| Modificada | Crítica (9.8) | 1.4% | — | Twsz Wifi Repeater Firmware | 20/9/2017 | 17/6/2026 | On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root") and can: 1. Read the entire file system; 2. Write to the file system; or 3. Execute any code that attacker desires (malicious or not). | |
| Modificada | Crítica (9.8) | 1.4% | — | Twsz Wifi Repeater Firmware | 20/9/2017 | 17/6/2026 | On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root"). The attacker can make a user that is connected to the repeater click on a malicious link that will log into the telnet and will infect the device with… | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Twsz Wifi Repeater Firmware | 20/9/2017 | 17/6/2026 | There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a crafted getpage parameter. | |
| Modificada | Alta (8.8) | 9.1% | 💥 Exploit | Twsz Wifi Repeater Firmware | 7/9/2017 | 17/6/2026 | T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user parameter to cgi-bin/webupg. |