Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability… | |
| Modificada | Alta (7.2) | 0.88% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability… | |
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability… | |
| Modificada | Alta (7.2) | 1.9% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A… | |
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A… | |
| Modificada | Alta (7.2) | 1.9% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A… | |
| Modificada | Alta (7.2) | 1.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.1% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.1% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 1.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection… | |
| Modificada | Alta (7.2) | 2.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple directory traversal vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A directory traversal vulnerability exists… | |
| Modificada | Alta (7.2) | 2.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple directory traversal vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A directory traversal vulnerability exists… | |
| Modificada | Alta (7.2) | 6.2% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability… | |
| Modificada | Alta (7.2) | 6.2% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple command execution vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability… | |
| Modificada | Alta (7.2) | 4.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection… | |
| Modificada | Alta (7.2) | 3.7% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection… | |
| Modificada | Alta (7.2) | 4.5% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection… | |
| Analizada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the adm.cgi set_sys_adm() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Analizada | Media (5.3) | 0.79% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the… | |
| Modificada | Alta (7.2) | 0.88% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the… | |
| Modificada | Alta (7.2) | 1.3% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the… | |
| Modificada | Alta (7.2) | 5.2% | — | Wavlink Wl-wn533a8 Firmware | 14/1/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection… |