Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.34%—Hosteng H0-ecom100 Firmware28/10/202217/6/2026
Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing a stack-based buffer overflow on Host Engineering H0-ECOM100 Communications Module Firmware versions v5.0.155 and prior. This may allow an attacker to crash the affected device or cause it to become…
ModificadaAlta (7.5)1.5%—Hosteng H0-ecom100 FirmwareHosteng H2-ecom100 FirmwareHosteng H4-ecom100 Firmware15/12/202017/6/2026
The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.
ModificadaMedia (5)1.3%—Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+413/4/201216/6/2026
The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.
ModificadaAlta (10)3.5%—Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+413/4/201216/6/2026
The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 does not require authentication, which allows remote attackers to perform unspecified functions via unknown vectors.
ModificadaMedia (4.3)1.0%—Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+413/4/201216/6/2026
Cross-site scripting (XSS) vulnerability in the web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.0%—Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+413/4/201216/6/2026
The ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 supports a maximum password length of 8 bytes, which makes it easier for remote attackers to obtain access via a brute-force attack.
ModificadaAlta (10)5.5%—Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+413/4/201216/6/2026
Buffer overflow in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to execute arbitrary code via long strings in unspecified parameters.