Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

30 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.47%—Tp-link Omada ControllerAI11/9/202611/9/2026
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized…
AplazadaMedia (6.9)0.67%—Tp-link Omada ControllerAI8/9/202621/9/2026
An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the…
AnalizadaMedia (5.7)0.30%—Tp-link Omada Fusion 2.5g FirmwareTp-link Omada Er707-m2 FirmwareTp-link Omada Er7206 FirmwareTp-link Omada Er706w Firmware+1053/8/202629/9/2026
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices…
AnalizadaMedia (5.8)0.31%—Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+1083/8/202629/9/2026
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of…
AnalizadaMedia (6.9)0.33%—Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+1083/8/202629/9/2026
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be…
AnalizadaAlta (8.2)0.32%—Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+1083/8/202629/9/2026
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications.
AnalizadaMedia (6.9)0.68%—Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+1083/8/202629/9/2026
A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and…
AnalizadaMedia (6.9)0.34%—Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+1093/8/202629/9/2026
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic…
AnalizadaAlta (7.7)0.22%—Tp-link Omada Fusion 2.5g FirmwareTp-link Omada Er707-m2 FirmwareTp-link Omada Er7206 FirmwareTp-link Omada Er706w Firmware+1053/8/202629/9/2026
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be…
AnalizadaAlta (7.7)0.97%—Tp-link Omada Sg2005p-pd FirmwareTp-link Omada Sg2008 FirmwareTp-link Omada Sg2008p FirmwareTp-link Omada Sg2016p Firmware+3513/3/202617/6/2026
The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the…
AnalizadaMedia (6.9)0.22%—Tp-link Omada Eap610 Firmware5/3/202617/6/2026
A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This results in temporary service unavailability until the device is rebooted. This issue affects Omada EAP610 firmware versions…
AnalizadaAlta (7.7)0.23%—Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+1013/2/202617/6/2026
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel.…
AnalizadaBaja (2)0.36%—Tp-link AginetTp-link DecoTp-link FestaTp-link Kasa+1013/2/202617/6/2026
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow…
AnalizadaMedia (5.1)0.28%—Tp-link Omada Controller26/1/202617/6/2026
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.
AnalizadaBaja (2.1)0.32%—Tp-link Omada Controller26/1/202617/6/2026
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.
AnalizadaAlta (8.3)0.45%—Tp-link Omada Controller26/1/202617/6/2026
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.
AnalizadaMedia (6)0.22%—Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+5223/1/202617/6/2026
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline…
AnalizadaMedia (5.7)0.20%—Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+122/1/202617/6/2026
A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker…
AplazadaAlta (8)1.1%—Omada IdentityAI27/11/202417/6/2026
Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History
AnalizadaMedia (4.2)0.38%—Tp-link Omada Er605 Firmware23/5/202417/6/2026
TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent attackers to access or spoof DDNS messages on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability. However, devices are vulnerable only if…
AnalizadaAlta (7.5)0.83%—Tp-link Omada Er605 Firmware23/5/202417/6/2026
TP-Link Omada ER605 Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability. However, devices are vulnerable only if…
AnalizadaAlta (7.5)0.80%—Tp-link Omada Er605 Firmware23/5/202417/6/2026
TP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability. However, devices are vulnerable…
AnalizadaAlta (7.5)0.51%—Tp-link Omada Er605 Firmware23/5/202417/6/2026
TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability.…
AnalizadaAlta (7.5)0.71%—Tp-link Omada Er605 Firmware23/5/202417/6/2026
TP-Link Omada ER605 PPTP VPN username Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability. However, devices are only…
AnalizadaAlta (8)0.97%—Tp-link Omada Er605 Firmware3/4/202417/6/2026
TP-Link Omada ER605 Access Control Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605. Authentication is required to exploit this vulnerability. The specific issue exists within the…