Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2546▼ 402 respecto a la semana anterior
Críticas / altas1312▲ 29 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)1.8%—Gl-inet A1300AIGl-inet Ax1800AIGl-inet Axt1800AIGl-inet Be1400AI+1317/8/202620/8/2026
A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. This affects an unknown part of the component Wi-Fi Timer Power-Schedule Feature. Executing a manipulation of the argument…
AplazadaMedia (5.3)0.39%—Gl-inet A1300AIGl-inet Ax1800AIGl-inet Axt1800AIGl-inet Be1400AI+1317/8/202620/8/2026
A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the…
AplazadaMedia (6.9)0.54%—Gl-inet A1300AIGl-inet Ax1800AIGl-inet Axt1800AIGl-inet Be1400AI+1317/8/202620/8/2026
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function COPY/MOVE of the component WebDAV Service. Such manipulation leads to…
AplazadaAlta (8.3)54%—Linksys E1000AILinksys E1200AILinksys E3200AI11/7/202516/6/2026
Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000.
AnalizadaMedia (6.7)0.46%—Linksys E1000 Firmware19/3/202417/6/2026
There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution.
ModificadaCrítica (9.8)0.64%—Motorola Ace1000 Firmware26/7/202217/6/2026
The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB mode using a hardcoded key. Similarly,…
ModificadaAlta (7.2)0.45%—Motorola Ace1000 Firmware26/7/202217/6/2026
The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where file system, kernel, package, bundle, or…
ModificadaCrítica (9.8)1.0%—Motorola Ace1000 Firmware26/7/202217/6/2026
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.
ModificadaCrítica (9.8)0.90%—Motorola Ace1000 Firmware26/7/202217/6/2026
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is controlled by 5 preconfigured accounts…
ModificadaAlta (8.8)0.46%—Motorola Ace1000 Firmware26/7/202217/6/2026
Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of…
ModificadaAlta (7.8)34%—Intel E1000Linux KernelLinux Kernel4/6/200916/6/2026
Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame…
ModificadaBaja (3.5)1.00%—Mailmarshal E10000 ApplianceMailmarshal Smtp2/10/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the delegated spam management feature in the Spam Quarantine Management (SQM) component in MailMarshal SMTP 6.0.3.8 through 6.3.0.0 allow user-assisted remote authenticated users to inject arbitrary web script or HTML via (1) the list of blocked senders or (2) the…