Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)16%⚠ Explotación activaTp-link Tl-wr841n FirmwareTp-link Mr6400 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+323/5/20243/9/2026
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw…
ModificadaCrítica (9.8)7.6%💥 PoCTp-link Wa901nd FirmwareTp-link Archer C5 FirmwareTp-link Archer C7 FirmwareTp-link Mr3420 Firmware+2326/12/202017/6/2026
A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND,…
ModificadaAlta (7.5)1.3%—Tp-link Tl-wr1043nd Firmware3/2/202016/6/2026
TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.
ModificadaAlta (7.2)34%💥 PoCTp-link Tl-wr1043nd Firmware20/6/201917/6/2026
Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerFoldersCfgRpm.htm.
ModificadaAlta (7.5)1.1%—Tp-link Tl-wr1043nd Firmware19/6/201917/6/2026
An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are encoded with URL encoding and base64, leading to easy decoding. Also, the username is cleartext,…
ModificadaCrítica (9.8)14%💥 ExploitTp-link Tl-wr1043nd Firmware19/6/201917/6/2026
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without knowledge of the credentials.
Orbitaley — Vulnerabilidades