Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.2)0.36%—Netgear Rax30 FirmwareNetgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware+18/9/202611/9/2026
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the…
AnalizadaMedia (5.2)0.39%—Netgear Cax30 FirmwareNetgear Rax30 FirmwareNetgear Rax5 FirmwareNetgear Raxe300 Firmware9/6/202623/7/2026
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
AnalizadaMedia (5.2)0.16%—Netgear Rax30 FirmwareNetgear Raxe300 Firmware11/11/202517/6/2026
Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device. Devices…
AnalizadaAlta (8.8)0.88%—Netgear Rax30 FirmwareNetgear Raxe300 FirmwareNetgear Rax40 FirmwareNetgear Rax35 Firmware+13/5/202417/6/2026
NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of…
AnalizadaAlta (8)1.2%—Netgear Rax30 FirmwareNetgear Raxe300 Firmware3/5/202417/6/2026
NETGEAR RAX30 logCtrl Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be…