Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.3% | — | Asus Rt-ax55 FirmwareAsus Rt-ax56u V2 FirmwareAsus Rt-ac86u Firmware | 7/9/2023 | 17/6/2026 | It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code… | |
| Modificada | Alta (7.2) | 1.3% | — | Asus Rt-ax55 FirmwareAsus Rt-ax56u V2 FirmwareAsus Rt-ac86u Firmware | 7/9/2023 | 17/6/2026 | It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution,… | |
| Modificada | Alta (7.2) | 1.4% | — | Asus Rt-ax55 FirmwareAsus Rt-ax56u V2 FirmwareAsus Rt-ac86u Firmware | 7/9/2023 | 17/6/2026 | It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system… | |
| Modificada | Alta (8.8) | 1.4% | — | Asus Rt-ac86u Firmware | 7/9/2023 | 17/6/2026 | ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. | |
| Modificada | Alta (8.8) | 1.4% | — | Asus Rt-ac86u Firmware | 7/9/2023 | 17/6/2026 | ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. | |
| Modificada | Alta (8.8) | 1.4% | — | Asus Rt-ac86u Firmware | 7/9/2023 | 17/6/2026 | ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. | |
| Modificada | Alta (8.8) | 1.4% | — | Asus Rt-ac86u Firmware | 7/9/2023 | 17/6/2026 | ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. | |
| Modificada | Alta (8.8) | 1.4% | — | Asus Rt-ac86u Firmware | 7/9/2023 | 17/6/2026 | ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services. | |
| Modificada | Crítica (9.8) | 1.1% | — | Asus Rt-ac86u FirmwareAsus Rt-ax56u V2 Firmware | 21/7/2023 | 17/6/2026 | It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability… | |
| Modificada | Alta (7.2) | 39% | — | Asus Rt-ac86u FirmwareAsus Rt-ax56u V2 Firmware | 21/7/2023 | 17/6/2026 | It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability… | |
| Modificada | Alta (7.2) | 0.89% | — | Asus Rt-ac86u Firmware | 2/6/2023 | 17/6/2026 | ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt system or terminate service. | |
| Modificada | Alta (8.8) | 1.2% | — | Asus Rt-ac86u Firmware | 2/6/2023 | 17/6/2026 | ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands, disrupt system or terminate service. | |
| Modificada | Crítica (9) | 0.98% | — | Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+89 | 5/7/2022 | 17/6/2026 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. | |
| Modificada | Alta (8.8) | 0.78% | — | Asus Rt-ac86u Firmware | 7/4/2022 | 17/6/2026 | ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service. | |
| Modificada | Alta (8.8) | 0.59% | — | Asus Rt-ac86u Firmware | 7/4/2022 | 17/6/2026 | ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service. | |
| Modificada | Media (6.5) | 0.40% | — | Asus Rt-ac86u Firmware | 7/4/2022 | 17/6/2026 | ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt. | |
| Modificada | Alta (7.5) | 2.2% | — | Asus Zenwifi AX (xt8) FirmwareAsus Rt-ax3000 FirmwareAsus Rt-ax55 FirmwareAsus Rt-ax56u Firmware+23 | 12/4/2021 | 17/6/2026 | In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a… | |
| Modificada | Crítica (9.8) | 5.2% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+10 | 15/10/2018 | 17/6/2026 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution | |
| Modificada | Crítica (9.8) | 5.4% | — | Asuswrt-merlin Project Rt-ac5300 FirmwareAsuswrt-merlin Project RT Ac1900p FirmwareAsuswrt-merlin Project Rt-ac68u FirmwareAsuswrt-merlin Project Rt-ac68p Firmware+10 | 15/10/2018 | 17/6/2026 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a… | |
| Modificada | Crítica (9.8) | 4.2% | — | Asus Rt-ac51u FirmwareAsus Rt-ac58u FirmwareAsus Rt-ac66u FirmwareAsus Rt-ac1750 Firmware+9 | 20/4/2018 | 17/6/2026 | ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3.0.0.4.382.50276; RT-AC86U and RT-AC2900 routers with firmware… | |
| Modificada | Crítica (9.8) | 3.6% | — | Asus Rt-ac66u FirmwareAsus Rt-ac68u FirmwareAsus Rt-ac86u FirmwareAsus Rt-ac88u Firmware+7 | 4/4/2018 | 17/6/2026 | Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and RT-AC3200 devices before 3.0.0.4.382.50010; and RT-AC5300 devices before 3.0.0.4.384.20287 allows OS… |