Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.45% | — | Wavlink Wl-wn579a3AI | 19/4/2026 | 17/6/2026 | A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected component is recommended. The vendor was… | |
| Aplazada | Alta (8.9) | 3.6% | — | Wavlink Wl-wn579a3AI | 16/3/2026 | 17/6/2026 | A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may… | |
| Analizada | Baja (2.1) | 8.4% | — | Wavlink Wl-wn579a3 Firmware | 16/2/2026 | 17/6/2026 | A weakness has been identified in Wavlink WL-WN579A3 up to 20210219. This affects the function AddMac of the file /cgi-bin/wireless.cgi. This manipulation of the argument macAddr causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be… | |
| Analizada | Media (5.3) | 8.7% | — | Wavlink Wl-wn579a3 Firmware | 16/2/2026 | 17/6/2026 | A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this… | |
| Analizada | Baja (2.1) | 8.4% | — | Wavlink Wl-wn579a3 Firmware | 16/2/2026 | 17/6/2026 | A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly… | |
| Analizada | Baja (2.1) | 8.7% | — | Wavlink Wl-wn579a3 Firmware | 16/2/2026 | 17/6/2026 | A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a manipulation of the argument key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor… | |
| Analizada | Baja (2.1) | 8.4% | — | Wavlink Wl-wn579a3 Firmware | 16/2/2026 | 17/6/2026 | A vulnerability was found in Wavlink WL-WN579A3 up to 20210219. This impacts the function multi_ssid of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument SSID2G2 results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor… | |
| Analizada | Crítica (9.8) | 1.8% | — | Wavlink Wl-wn579a3 Firmware | 20/5/2025 | 17/6/2026 | A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input. | |
| Analizada | Crítica (9.8) | 1.8% | — | Wavlink Wl-wn579a3 Firmware | 20/5/2025 | 17/6/2026 | A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input. | |
| Analizada | Crítica (9.8) | 1.8% | — | Wavlink Wl-wn579a3 Firmware | 20/5/2025 | 17/6/2026 | A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input. |