Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.15%—AxesshAI22/3/202617/6/2026
Axessh 4.2 contains a stack-based buffer overflow vulnerability in the log file name field that allows local attackers to execute arbitrary code by supplying an excessively long filename. Attackers can overflow the buffer at offset 214 bytes to overwrite the instruction pointer and execute shellcode with system…
AplazadaMedia (6.9)0.17%—AxesshAI22/3/202617/6/2026
Axessh 4.2 contains a denial of service vulnerability in the logging configuration that allows local attackers to crash the application by supplying an excessively long string in the log file name field. Attackers can enable session logging, paste a buffer of 500 or more characters into the log file name parameter,…
AplazadaMedia (6.1)0.25%—Zucchetti Axess XA4AIZucchetti Axess X3AIZucchetti Axess X3bioAIZucchetti Axess X4AI+418/3/20265/7/2026
A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices, including XA4, X3/X3BIO, X4, X7, and XIO / i-door / i-door+. The vulnerability is caused by improper sanitization of user-supplied input in the dirBrowse parameter of the…
AplazadaMedia (5.1)0.20%—Zucchetti Axess Cloki Access ControlAI23/12/202517/6/2026
Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to manipulate access control settings without user interaction. Attackers can craft malicious web pages with hidden forms to disable or modify access control parameters by tricking authenticated users…
AplazadaAlta (7.5)0.53%—Axess ACSAI27/1/202517/6/2026
In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenticated attackers to cause a permanent Denial of Service via crafted TR069 requests on TCP port 9675 or 7547. Rebooting does not resolve the permanent Denial of Service.
AplazadaCrítica (9.8)0.73%—Axiros Axess Auto Configuration ServerAI24/6/202417/6/2026
Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution.
ModificadaMedia (5.4)0.51%—Axesstel Mu553s Firmware13/9/201717/6/2026
On the Axesstel MU553S MU55XS-V1.14, there is a Stored Cross Site Scripting vulnerability in the APN parameter under the "Basic Settings" page.
ModificadaCrítica (9.8)1.4%—Axesstel Mu553s Firmware13/9/201717/6/2026
Axesstel MU553S MU55XS-V1.14 devices have a default password of admin for the admin account.
ModificadaAlta (8.8)0.45%—Axesstel Mu553s Firmware13/9/201717/6/2026
Cross-Site Request Forgery (CSRF) exists in cgi-bin/ConfigSet on Axesstel MU553S MU55XS-V1.14 devices.
ModificadaMedia (5.8)0.85%—Axesstel MV 410r5/7/200916/6/2026
The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts, which makes it easier for remote attackers to avoid detection of cross-site request forgery (CSRF) attacks, as demonstrated by a redirect from the cgi-bin/wireless.cgi script.
ModificadaMedia (4.3)0.87%—Axesstel MV 410r5/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)1.6%—Axesstel MV 410r5/7/200916/6/2026
cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to cause a denial of service (configuration reset) via a RESTORE=RESTORE query string.
ModificadaAlta (7.5)1.2%—Axesstel MV 410r5/7/200916/6/2026
The web interface on the Axesstel MV 410R relies on client-side JavaScript code to validate input, which allows remote attackers to send crafted data, and possibly have unspecified other impact, via a client that does not process JavaScript.
ModificadaMedia (5)0.65%—Axesstel MV 410r5/7/200916/6/2026
The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
ModificadaAlta (7.8)1.2%—Axesstel MV 410r5/7/200916/6/2026
The Axesstel MV 410R allows remote attackers to cause a denial of service via a flood of SYN packets, a related issue to CVE-1999-0116.
ModificadaAlta (10)2.1%—Axesstel MV 410r5/7/200916/6/2026
The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it easier for remote attackers to obtain access.
ModificadaAlta (10)2.6%—Axesstel Akw-d80031/7/200816/6/2026
The Axesstel AXW-D800 modem with D2_ETH_109_01_VEBR Jun-14-2006 software does not require authentication for (1) etc/config/System.html, (2) etc/config/Network.html, (3) etc/config/Security.html, (4) cgi-bin/sysconf.cgi, and (5) cgi-bin/route.cgi, which allows remote attackers to change the modem's configuration via…