Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.2) | 0.36% | — | Netgear Rax30 FirmwareNetgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware+1 | 8/9/2026 | 11/9/2026 | An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the… | |
| Analizada | Media (5.2) | 0.39% | — | Netgear Cax30 FirmwareNetgear Rax30 FirmwareNetgear Rax5 FirmwareNetgear Raxe300 Firmware | 9/6/2026 | 23/7/2026 | An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. | |
| Analizada | Media (5.2) | 0.16% | — | Netgear Rax30 FirmwareNetgear Raxe300 Firmware | 11/11/2025 | 17/6/2026 | Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device. Devices… | |
| Analizada | Alta (8.8) | 0.88% | — | Netgear Rax30 FirmwareNetgear Raxe300 FirmwareNetgear Rax40 FirmwareNetgear Rax35 Firmware+1 | 3/5/2024 | 17/6/2026 | NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of… | |
| Analizada | Alta (8) | 1.2% | — | Netgear Rax30 FirmwareNetgear Raxe300 Firmware | 3/5/2024 | 17/6/2026 | NETGEAR RAX30 logCtrl Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be… |