Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)1.8%—Tp-link Tl-wr802n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware16/3/20261/7/2026
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in…
AnalizadaMedia (6.5)16%⚠ Explotación activaTp-link Tl-wr841n FirmwareTp-link Mr6400 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+323/5/20243/9/2026
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw…
AnalizadaAlta (8.8)0.91%—Tp-link Tl-wr841n FirmwareTp-link Tl-wr840n Firmware3/5/202417/6/2026
TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
ModificadaMedia (6.8)0.42%—Tp-link Tl-wr840n Firmware25/5/202217/6/2026
TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the UART port via a serial connection and execute commands as the root user without authentication.
ModificadaAlta (7.2)1.6%—Tp-link Tl-wr840n Firmware18/4/202217/6/2026
Tp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset feature.
ModificadaAlta (7.2)1.3%—Tp-link Tl-wr840n Firmware28/3/202217/6/2026
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
ModificadaAlta (7.2)1.3%—Tp-link Tl-wr840n Firmware28/3/202217/6/2026
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
ModificadaAlta (7.2)1.3%—Tp-link Tl-wr840n Firmware28/3/202217/6/2026
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
ModificadaAlta (7.2)1.3%—Tp-link Tl-wr840n Firmware28/3/202217/6/2026
TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
ModificadaCrítica (9.8)36%—Tp-link Tl-wr840n Firmware25/2/20229/7/2026
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
ModificadaAlta (7.5)3.5%—Tp-link Tl-wr840n Firmware25/2/20229/7/2026
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
ModificadaCrítica (9.8)59%—Tp-link Tl-wr840n Firmware25/2/20229/7/2026
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
ModificadaCrítica (9.8)40%—Tp-link Tl-wr840n Firmware25/2/20229/7/2026
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
ModificadaCrítica (9.8)76%—Tp-link Tl-wr840n Firmware13/11/20219/7/2026
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
ModificadaMedia (6.4)0.75%—Tp-link Tl-wr840n Firmware19/8/202117/6/2026
In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow
ModificadaCrítica (9.8)9.8%—Tp-link Tl-wr840n Firmware6/1/202117/6/2026
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function…
ModificadaCrítica (9.8)7.6%—Tp-link Wa901nd FirmwareTp-link Archer C5 FirmwareTp-link Archer C7 FirmwareTp-link Mr3420 Firmware+2326/12/202017/6/2026
A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND,…
ModificadaAlta (8.8)4.0%—Tp-link Tl-wr840n Firmware22/8/201917/6/2026
The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.
ModificadaMedia (4.8)1.8%—Tp-link Tl-wr840n Firmware24/5/201917/6/2026
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the…
ModificadaMedia (4.9)1.7%—Tp-link Wr840n Firmware16/4/201917/6/2026
The ping feature in the Diagnostic functionality on TP-LINK WR840N v2 Firmware 3.16.9 Build 150701 Rel.51516n devices allows remote attackers to cause a denial of service (HTTP service termination) by modifying the packet size to be higher than the UI limit of 1472.
ModificadaAlta (7.5)1.9%—Tp-link Tl-wr840n Firmware29/3/201917/6/2026
TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.
ModificadaAlta (7.5)8.3%—Tp-link Tl-wr840n Firmware15/8/201817/6/2026
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
ModificadaCrítica (9.8)68%—Tp-link Tl-wr840n FirmwareTp-link Tl-wr841n Firmware4/6/201817/6/2026
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer:…
ModificadaMedia (6.8)0.98%—Tp-link Tl-wr840n Firmware9/1/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firmware before 3.13.27 build 141120 allows remote attackers to hijack the authentication of administrators for requests that change router settings via a configuration file import.