Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2636▼ 272 respecto a la semana anterior
Críticas / altas1349▲ 92 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)1.8%—Trendnet Tew-755apAI19/8/202621/8/2026
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the…
AplazadaAlta (8.6)0.85%—Trendnet Tew-755apAI19/8/202621/8/2026
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow. The attack can be executed remotely. The…
AplazadaAlta (8.6)0.85%—Trendnet Tew-755apAI19/8/202625/8/2026
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
ModificadaCrítica (9.8)0.97%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_24g function.
ModificadaCrítica (9.8)0.97%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.
ModificadaCrítica (9.8)2.3%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function.
ModificadaCrítica (9.8)2.3%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the del_num parameter in the icp_delete_img (sub_41DEDC) function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the update_file_name parameter in the auto_up_fw (sub_420A04) function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the do_sta_enrollee_wifi function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the set_sta_enrollee_pin_5g function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reject_url parameter in the reject (sub_41BD60) function.
ModificadaCrítica (9.8)0.97%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function.
ModificadaCrítica (9.8)0.97%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_option parameter in the tools_netstat (sub_41E730) function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.
ModificadaCrítica (9.8)0.97%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow (sub_415B00) function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function.
ModificadaCrítica (9.8)0.97%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_deny (sub_415D7C) function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the login_name parameter in the do_graph_auth (sub_4061E0) function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.
ModificadaCrítica (9.8)0.87%—Trendnet Tew-755ap Firmware30/12/202217/6/2026
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.
ModificadaMedia (6.5)0.81%—Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware10/8/202117/6/2026
A Format String vulnerablity exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service due to a logic bug at address 0x40dcd0 when calling fprintf with "%s: key len = %d, too long\n" format. The two…
ModificadaAlta (7.5)0.96%—Trendnet Tew-755ap FirmwareTrendnet Tew-755ap2kac FirmwareTrendnet Tew-821dap2kac FirmwareTrendnet Tew-825dap Firmware10/8/202117/6/2026
Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending the POST request to apply_cgi via the lang action without a language key.