Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
309 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the initial (factory-default) configuration, the device can be configured with the null string password. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration. | |
| Analizada | Media (5.1) | 0.27% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication. | |
| Analizada | Media (6.9) | 0.60% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition. | |
| Analizada | Alta (7.1) | 0.46% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing the password by sending a crafted packet. | |
| Analizada | Alta (8.2) | 0.27% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle attack. | |
| Analizada | Media (6.9) | 0.40% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without authentication. | |
| Analizada | Crítica (9.3) | 0.71% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device. | |
| Analizada | Alta (8.7) | 0.65% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device. | |
| Analizada | Media (5.5) | 0.67% | — | Edimax Br-6208ac Firmware | 6/2/2026 | 17/6/2026 | A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor… | |
| Analizada | Crítica (9.3) | 0.77% | — | Elecom Wab-s300iw-pd FirmwareElecom Wab-s733iw-pd FirmwareElecom Wrc-x1500gsa-b FirmwareElecom Wrc-x1500gs-b Firmware+4 | 3/2/2026 | 17/6/2026 | Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution. | |
| Analizada | Crítica (9.8) | 27% | — | Edimax Br-6208ac Firmware | 9/1/2026 | 17/6/2026 | EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.39% | — | UI Airmax AC FirmwareUI Airmax M FirmwareUI Airfiber Af60-xg FirmwareUI Airfiber Af60 Firmware | 8/1/2026 | 30/7/2026 | A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. | |
| Modificada | Baja (2) | 0.26% | — | Edimax Br-6208ac Firmware | 30/12/2025 | 17/6/2026 | A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of the file /goform/formALGSetup of the component Web-based Configuration Interface. This manipulation of the argument wlan-url causes open redirect. The attack is possible to be carried out remotely. The… | |
| Modificada | Media (5.5) | 5.1% | — | Edimax Br-6208ac Firmware | 30/12/2025 | 17/6/2026 | A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be… | |
| Analizada | Media (5.5) | 3.8% | — | Edimax Br-6208ac Firmware | 30/12/2025 | 17/6/2026 | A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component Web-based Configuration Interface. The manipulation of the argument rootAPmac leads to command injection. Remote exploitation of the attack is possible. The… | |
| Analizada | Baja (2.1) | 0.53% | — | Edimax Br-6208ac Firmware | 19/12/2025 | 17/6/2026 | A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon Service. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. Edimax confirms this issue: "This product is no longer available… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+36 | 8/7/2025 | 17/6/2026 | Memory corruption while processing event close when client process terminates abruptly. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+35 | 8/7/2025 | 17/6/2026 | Memory corruption while processing multiple simultaneous escape calls. | |
| Modificada | Alta (8.8) | 0.41% | — | Edimax Br-6476ac Firmware | 27/1/2025 | 5/7/2026 | Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/getWifiBasic. | |
| Modificada | Alta (8.8) | 5.4% | — | Edimax Br-6476ac Firmware | 27/1/2025 | 5/7/2026 | Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to… | |
| Modificada | Alta (8.8) | 0.31% | — | Edimax Br-6476ac Firmware | 27/1/2025 | 5/7/2026 | In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands. | |
| Modificada | Media (5.2) | 0.29% | — | Edimax Br-6476ac Firmware | 27/1/2025 | 5/7/2026 | Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via /goform/setStaticRoute, /goform/fromSetFilterUrlFilter, and /goform/fromSetFilterClientFilter. |