Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.2) | 0.34% | — | Tp-link TL Wr845nAITp-link TL Wr850nAITp-link TL Wr902acAITp-link Archer C20AI+1 | 27/7/2026 | 11/8/2026 | A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis.… | |
| Modificada | Media (5.9) | 0.45% | — | Tp-link Archer Mr200 FirmwareTp-link Archer C20 FirmwareTp-link Tl-wr850n FirmwareTp-link Tl-wr845n Firmware | 5/2/2026 | 17/6/2026 | The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the… | |
| Modificada | Crítica (9.8) | 1.2% | — | Tp-link Tl-wr845n Firmware | 26/2/2025 | 17/6/2026 | TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained by analyzing downloaded firmware or via a brute force attack through physical access to the router. NOTE: The supplier has stated that… | |
| Analizada | Alta (8) | 0.24% | — | Tp-link Tl-wr845n Firmware | 10/12/2024 | 17/6/2026 | TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack. | |
| Analizada | Crítica (9.8) | 0.34% | — | Tp-link Tl-wr845n Firmware | 10/12/2024 | 17/6/2026 | TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset. | |
| Analizada | Alta (8) | 0.42% | — | Tp-link Tl-wr845n Firmware | 10/12/2024 | 17/6/2026 | TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account. |