Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.81% | — | Rdkb WebuiAI | 19/8/2026 | 3/9/2026 | Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary code, via a crafted multipart/form-data request. | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | Rdkb-webuiAI | 19/8/2026 | 3/9/2026 | Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values. | |
| Modificada | Media (6.7) | 0.12% | — | Linuxfoundation YoctoRdkcentral RdkbGoogle AndroidOpenwrt | 4/3/2024 | 17/6/2026 | In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528255; Issue ID: ALPS08528255. | |
| Modificada | Baja (3.3) | 0.08% | — | Linuxfoundation YoctoRdkcentral RdkbGoogle AndroidOpenwrt | 15/5/2023 | 17/6/2026 | In mnld, there is a possible leak of GPS location due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07735968 / ALPS07884552 (For MT6880, MT6890, MT6980, MT6980D and MT6990… | |
| Modificada | Alta (8.8) | 1.8% | — | Rdkcentral Rdkb Ccsppandm | 20/6/2019 | 17/6/2026 | A heap-based buffer over-read in Service_SetParamStringValue in cosa_x_cisco_com_ddns_dml.c of the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve information disclosure and code execution by crafting an AJAX call responsible for DDNS configuration with an exactly 64-byte… | |
| Modificada | Alta (8.8) | 2.4% | — | Rdkcentral Rdkb Ccsppandm | 20/6/2019 | 17/6/2026 | A heap-based buffer overflow in cosa_dhcpv4_dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve remote code execution by crafting a long buffer in the "Comment" field of an IP reservation form in the admin panel. This is related to the CcspCommonLibrary module. | |
| Modificada | Alta (7.5) | 1.6% | — | Rdkcentral Rdkb Ccsppandm | 20/6/2019 | 17/6/2026 | A shell injection issue in cosa_wifi_apis.c in the RDK RDKB-20181217-1 CcspWifiAgent module allows attackers with login credentials to execute arbitrary shell commands under the CcspWifiSsp process (running as root) if the platform was compiled with the ENABLE_FEATURE_MESHWIFI macro. The attack is conducted by… | |
| Modificada | Media (6.5) | 0.93% | — | Rdkcentral Rdkb Ccsppandm | 20/6/2019 | 17/6/2026 | Incorrect access control in actionHandlerUtility.php in the RDK RDKB-20181217-1 WebUI module allows a logged in user to control DDNS, QoS, RIP, and other privileged configurations (intended only for the network operator) by sending an HTTP POST to the PHP backend, because the page filtering for non-superuser (in… |