Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)1.8%—Wavlink Wl-wn535k3 Firmware2/9/202517/6/2026
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
AnalizadaMedia (6.5)1.1%—Wavlink Wl-wn535k3 Firmware2/9/202517/6/2026
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
AnalizadaCrítica (9.8)1.8%—Wavlink Wn535k3 Firmware14/7/202517/6/2026
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
ModificadaCrítica (9.8)33%💥 ExploitWavlink Wl-wn535k2 FirmwareWavlink Wl-wn535k3 Firmware20/7/202217/6/2026
A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.
ModificadaCrítica (9.8)79%💥 ExploitWavlink Wl-wn535k2 FirmwareWavlink Wl-wn535k3 Firmware20/7/202217/6/2026
A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection. The exploit has been disclosed to the public and may be used.
ModificadaCrítica (9.8)30%💥 ExploitWavlink Wl-wn535k2 FirmwareWavlink Wl-wn535k3 Firmware20/7/202217/6/2026
A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used.
Orbitaley — Vulnerabilidades