Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2578▼ 368 respecto a la semana anterior
Críticas / altas1326▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.2% | — | Dlink Dsl-2640b Firmware | 20/4/2020 | 17/6/2026 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login with high privileges. The logged-in user can perform critical tasks and take full control of the device. | |
| Modificada | Crítica (9.1) | 1.6% | — | Dlink Dsl-2640b Firmware | 20/4/2020 | 17/6/2026 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated URL. | |
| Modificada | Crítica (9.8) | 2.5% | — | Dlink Dsl-2640b Firmware | 20/4/2020 | 17/6/2026 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin password) with no authentication. | |
| Modificada | Alta (8.8) | 2.6% | — | Dlink Dsl-2640b Firmware | 20/4/2020 | 17/6/2026 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests supplied to the device's web servers, is vulnerable to a remotely exploitable stack-based buffer overflow. Unauthenticated exploitation is possible by combining this vulnerability with CVE-2020-9277. | |
| Modificada | Crítica (9.8) | 1.7% | — | Dlink Dsl-2640b Firmware | 20/4/2020 | 17/6/2026 | An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltration of administrative credentials. | |
| Modificada | Alta (7.5) | 1.4% | — | D-link Dsl-2640b Firmware | 5/3/2020 | 17/6/2026 | An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the administrative interface can install firmware of their choice. | |
| Modificada | Media (6.8) | 2.4% | — | Dlink Dsl-2640b FirmwareDlink Dsl-2640b | 8/10/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter. |