Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.49% | — | Contec Fx5000AIContec Fx4000AIContec Fx3000AI | 14/9/2026 | 16/9/2026 | Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP. | |
| Aplazada | Media (4.8) | 0.24% | — | Contec Fx5000 SeriesAIContec Fx4000 SeriesAIContec Fx3000 SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (8.7) | 1.9% | — | Contec Fx5000 SeriesAIContec Fx4000 SeriesAIContec Fx3000 SeriesAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (6.9) | 2.1% | — | Gl-inet A1300AIGl-inet Ax1800AIGl-inet Axt1800AIGl-inet Mt2500AI+4 | 17/8/2026 | 20/8/2026 | A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file /usr/bin/gl_nas_sys of the component NAS Command Service. The manipulation results in os command injection. The attack may be launched remotely.… | |
| Aplazada | Media (5.3) | 1.8% | — | Gl-inet A1300AIGl-inet Ax1800AIGl-inet Axt1800AIGl-inet Be1400AI+13 | 17/8/2026 | 20/8/2026 | A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. This affects an unknown part of the component Wi-Fi Timer Power-Schedule Feature. Executing a manipulation of the argument… | |
| Aplazada | Media (5.3) | 0.39% | — | Gl-inet A1300AIGl-inet Ax1800AIGl-inet Axt1800AIGl-inet Be1400AI+13 | 17/8/2026 | 20/8/2026 | A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the… | |
| Aplazada | Media (6.9) | 0.54% | — | Gl-inet A1300AIGl-inet Ax1800AIGl-inet Axt1800AIGl-inet Be1400AI+13 | 17/8/2026 | 20/8/2026 | A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function COPY/MOVE of the component WebDAV Service. Such manipulation leads to… | |
| Aplazada | Media (5.3) | 0.51% | — | Gl-inet Mt3000AIGl-inet Mt6000AIGl-inet Be9300AIGl-inet Be3600AI+7 | 3/8/2026 | 12/8/2026 | A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may… | |
| Aplazada | Media (5.3) | 0.35% | — | Gl-inet E5800AIGl-inet E750AIGl-inet X2000AIGl-inet X3000AI+2 | 3/8/2026 | 12/8/2026 | A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor… | |
| Aplazada | Baja (2.3) | 0.20% | — | Gl-inet A1300AIGl-inet Ax1800AIGl-inet Axt1800AIGl-inet Mt2500AI+4 | 8/6/2026 | 23/7/2026 | A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of… | |
| Pendiente de análisis | Crítica (9.8) | 0.76% | — | Gl-inet Gl-mt3000AIGl-inet Gl-ar300mAIGl-inet Gl-b1300AIGl-inet Gl-ax1800AI+5 | 8/5/2026 | 17/6/2026 | Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular expression. For example, this affects version 4.3.7 on GL-MT3000 GL-AR300M GL-B1300 GL-AX1800 GL-AR750S GL-MT2500 GL-AXT1800… | |
| Analizada | Alta (7.1) | 1.2% | — | NEC Aterm Wg2600hs FirmwareNEC Aterm Wf1200cr FirmwareNEC Aterm Wg1200cr FirmwareNEC Aterm Wg2600hp4 Firmware+5 | 27/3/2026 | 17/6/2026 | OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. | |
| Analizada | Media (6.3) | 0.25% | — | NEC Aterm Wg1200hp4 FirmwareNEC Aterm Wg2600hs FirmwareNEC Aterm Wf1200cr FirmwareNEC Aterm Wg1200cr Firmware+17 | 27/3/2026 | 17/6/2026 | Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network. | |
| Analizada | Media (6.3) | 0.23% | — | NEC Aterm Wg2600hs FirmwareNEC Aterm Wf1200cr FirmwareNEC Aterm Wg1200cr FirmwareNEC Aterm Wg2600hp4 Firmware+16 | 27/3/2026 | 17/6/2026 | Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the settings via network. | |
| Analizada | Media (6) | 0.43% | — | Iptime T5008 FirmwareIptime Ax2004m FirmwareIptime Ax3000q FirmwareIptime Ax6000m Firmware | 27/2/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Networks, Inc. IpTIME AX2004M, EFM-Networks, Inc. IpTIME AX3000Q, EFM-Networks, Inc. IpTIME AX6000M allows Authentication Bypass.This issue affects ipTIME T5008: through 15.26.8; ipTIME AX2004M: through… | |
| Modificada | Crítica (9.8) | 1.1% | — | Jdcloud Ax1800 FirmwareJdcloud Ax3000 FirmwareJdcloud Ax6600 FirmwareJdcloud Be6500 Firmware+2 | 30/12/2025 | 5/7/2026 | JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability. | |
| Aplazada | Alta (8.7) | 0.97% | — | Buffalo Wrc-x3000gsAIBuffalo Wrc-x3000gsaAIBuffalo Wrc-x3000gsnAI | 24/6/2025 | 17/6/2026 | WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If a remote authenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be… | |
| Aplazada | Alta (8.6) | 0.40% | — | Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+19 | 26/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl,… | |
| Aplazada | Media (5.1) | 0.22% | — | Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+19 | 26/4/2025 | 17/6/2026 | A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000… | |
| Aplazada | Media (6.9) | 0.36% | — | Gl-inet GL A1300 Slate PlusAIGl-inet GL Ar300m16 ShadowAIGl-inet GL Ar300m ShadowAIGl-inet GL Ar750 CretaAI+19 | 26/4/2025 | 17/6/2026 | A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000… | |
| Aplazada | Alta (7.5) | 0.54% | — | NEC Corporation Aterm Wg2600hsAINEC Corporation Aterm Wf1200crsAINEC Corporation Aterm Wg1200crsAINEC Corporation Aterm Gb1200peAI+5 | 15/1/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier,… | |
| Aplazada | Media (4.8) | 0.23% | — | NEC Corporation Aterm Wg2600hsAINEC Corporation Aterm Wg2600hp4AINEC Corporation Aterm Wg2600hm4AINEC Corporation Aterm Wg2600hs2AI+2 | 15/1/2025 | 17/6/2026 | Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the… | |
| Analizada | Alta (8.8) | 0.27% | — | Gl-inet Mt6000 FirmwareGl-inet Mt3000 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 Firmware+17 | 24/10/2024 | 17/6/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control. | |
| Analizada | Alta (8.8) | 0.67% | — | Gl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 FirmwareGl-inet B3000 Firmware+17 | 24/10/2024 | 17/6/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path. | |
| Analizada | Alta (8) | 0.49% | — | Gl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 FirmwareGl-inet B3000 Firmware+17 | 24/10/2024 | 17/6/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication… |