Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.22% | — | Insta InstinaknxserviceappAI | 6/8/2026 | 12/8/2026 | A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of… | |
| Aplazada | Media (5.9) | 0.15% | — | ABB KNX Update ToolAIBJE KNX Update ToolAI | 17/7/2026 | 17/7/2026 | Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175. | |
| Aplazada | Media (6.9) | 0.84% | — | Jung Smart Panel KNXAI | 10/2/2026 | 17/6/2026 | JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the embedded web interface. The application fails to properly validate file path input, allowing remote, unauthenticated attackers to access arbitrary files on the underlying filesystem within the… | |
| Aplazada | Alta (8.5) | 0.32% | — | ABB Eibport V3 KNXAIABB Eibport V3 KNX GSMAI | 7/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2. | |
| Aplazada | Crítica (9.4) | 0.50% | — | Eibport V3 KNXAIEibport V3 KNX GSMAI | 4/6/2025 | 17/6/2026 | This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by the integrated web Server of EIBPORT. This issue affects EIBPORT V3 KNX: through 3.9.8; EIBPORT V3 KNX GSM: through 3.9.8. | |
| Analizada | Alta (7.5) | 1.3% | ⚠ Explotación activa | KNX Connection Authorization | 29/8/2023 | 16/7/2026 | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not… | |
| Modificada | Media (6.1) | 0.48% | — | Gira KNX IP Router Firmware | 30/6/2023 | 17/6/2026 | The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status code if a path is accessed that does not exist. However, the value of the path is reflected in the response. As the application will reflect the supplied path without context-sensitive HTML encoding,… | |
| Modificada | Alta (7.5) | 1.3% | — | Gira KNX IP Router Firmware | 29/6/2023 | 17/6/2026 | The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-traversal sequences in the URL. | |
| Modificada | Alta (8.8) | 0.36% | — | Schneider-electric Merten Instabus Tastermodul 1fach System M FirmwareSchneider-electric Merten Instabus Tastermodul 2fach System M FirmwareSchneider-electric Merten Tasterschnittstelle 4fach Plus FirmwareSchneider-electric Merten KNX Argus 180/2,20m UP System Firmware+3 | 18/4/2023 | 17/6/2026 | A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation. | |
| Modificada | Alta (7.5) | 0.95% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 11/2/2022 | 17/6/2026 | A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior) | |
| Modificada | Media (6.1) | 0.60% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 9/2/2022 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious JavaScript code inside the target browser. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser… | |
| Modificada | Alta (8.1) | 0.41% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 9/2/2022 | 17/6/2026 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit a rogue website. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk)… | |
| Modificada | Crítica (9.8) | 1.1% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 9/2/2022 | 17/6/2026 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and… | |
| Modificada | Media (5.3) | 0.79% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 9/2/2022 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and… | |
| Modificada | Media (5.5) | 0.32% | — | KNX Engineering Tool Software 6 | 9/11/2021 | 17/6/2026 | KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this because it is not the responsibility of the ETS to securely store cryptographic key material when it… | |
| Modificada | Alta (8.8) | 0.42% | 💥 PoC | KNX Engineering Tool Software 5 | 19/7/2021 | 17/6/2026 | KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (7.5) | 1.5% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX Firmware | 31/8/2020 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used. | |
| Modificada | Alta (7.5) | 1.4% | — | ISE Smart Connect KNX Vaillant | 14/8/2020 | 17/6/2026 | ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service. | |
| Modificada | Alta (8.3) | 1.5% | — | Schneider-electric Wiser FOR KNX FirmwareSchneider-electric Spacelynk Firmware | 17/9/2019 | 17/6/2026 | A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known as homeLYnk), which could cause loss of control when an attacker bypasses the authentication. | |
| Modificada | Alta (7.5) | 3.4% | — | ABB Pm554-tp-eth FirmwarePhoenixcontact ILC 151 ETH FirmwareSchneider-electric Modicon M221 FirmwareSiemens 6es7211-1ae40-0xb0 Firmware+6 | 17/4/2019 | 17/6/2026 | ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets. | |
| Modificada | Alta (7.5) | 1.4% | — | Schneider-electric Homelynk FirmwareSchneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX Firmware | 3/7/2018 | 17/6/2026 | In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access could allow an attacker unauthorized access. | |
| Modificada | Crítica (9.8) | 6.2% | 💥 PoC | KNX ETS | 29/8/2017 | 17/6/2026 | Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute arbitrary code via a crafted KNXnet/IP UDP packet. |