Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 4.9% | 💥 Exploit | ZTE Zxhn H108n R1A FirmwareZTE Zxv10 W300 Firmware | 30/12/2015 | 17/6/2026 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248. | |
| Modificada | Media (6.1) | 2.7% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to read arbitrary files via a full pathname in the getpage parameter. | |
| Modificada | Media (4.9) | 5.5% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | ZTE Zxhn H108n R1A Firmware | 30/12/2015 | 17/6/2026 | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/webproc HTML source code, a different vulnerability than CVE-2015-8703. |