1310 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2019-3586
McAfee Endpoint Security (ENS) Networking
7.5
HIGH
EPSS
0.3%
2019 CWE-693 1 PoC

Protection Mechanism Failure in the Firewall in McAfee Endpoint Security (ENS) 10.x prior to 10.6.1 May 2019 update allows context-dependent attackers to circumvent ENS protection where GTI flagged IP addresses are not blocked by the ENS Firewall via specially crafted malicious sites where the GTI reputation is carefully manipulated and does not correctly trigger the ENS Firewall to block the connection.

CVE-2019-5055
N300 WNR2000v5 Networking
7.5
HIGH
EPSS
1.4%
2019 CWE-476 1 PoC

An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) wireless router. A SOAP request sent in an invalid sequence to the <WFAWLANConfig:1#PutMessage> service can cause a null pointer dereference, resulting in the hostapd service crashing. An unauthenticated attacker can send a specially-crafted SOAP request to trigger this vulnerability.

CVE-2019-15993
Cisco Small Business 250 Series Smart Switches Software Web Networking
7.5
HIGH
EPSS
12.3%
2019 CWE-16 1 PoC

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.

CVE-2019-13608
🔥 KEV Software Genérico Networking ⚡ nuclei
7.5
HIGH
EPSS
71.3%
2019 0 PoCs

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

CVE-2019-0028
Junos OS Networking
7.5
HIGH
EPSS
0.6%
2019 CWE-404 1 PoC

On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP session restart on a remote peer that has the graceful restart mechanism enabled may cause the local routing protocol daemon (RPD) process to crash and restart. By simulating a specific BGP session restart, an attacker can repeatedly crash the RPD process causing prolonged denial of service (DoS). Graceful restart helper mode for BGP is enabled by default. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos

CVE-2019-5105
3S Networking
7.5
HIGH
EPSS
0.2%
2019 CWE-119 1 PoC

An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker can send a packet to a device running the GatewayService.exe to trigger this vulnerability. All variants of the CODESYS V3 products in all versions prior V3.5.16.10 containing the CmpRouter or CmpRouterEmbedded component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODES

CVE-2021-41291
ECS Router Controller ECS (FLASH) Networking ⚡ nuclei
7.5
HIGH
EPSS
91.7%
2021 CWE-22 0 PoCs

ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Manager, unauthenticated attackers can remotely disclose directory content on the affected device.

CVE-2021-33555
WHA-GW-F2D2-0-AS- Z2-ETH Networking
7.5
HIGH
EPSS
0.9%
2021 CWE-22 1 PoC

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.

CVE-2021-37316
Software Genérico Networking Database Cloud
7.5
HIGH
EPSS
0.4%
2021 1 PoC

SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.

CVE-2021-34561
WHA-GW-F2D2-0-AS- Z2-ETH Networking
7.5
HIGH
EPSS
0.3%
2021 CWE-350 1 PoC

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.

CVE-2021-36369
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2021 1 PoC

An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass. Thus, it allows an attacker to abuse a forwarded agent for logging on to another server unnoticed.

CVE-2021-41293
ECS Router Controller ECS (FLASH) Networking ⚡ nuclei
7.5
HIGH
EPSS
89.6%
2021 CWE-22 0 PoCs

ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific POST parameter, unauthenticated attackers can remotely disclose arbitrary files on the affected device and disclose sensitive and system information.

CVE-2021-27857
WARP Networking
7.5
HIGH
EPSS
0.5%
2021 CWE-862 1 PoC

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly guess the hostname of the target system since the hostname is used as part of the configuration archive file name. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA003.

CVE-2021-20030
SonicWall GMS Networking
7.5
HIGH
EPSS
1.1%
2021 CWE-22 1 PoC

SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing application's binaries and configuration files.

CVE-2017-6627
🔥 KEV Cisco IOS and Cisco IOS XE Networking
7.5
HIGH
EPSS
10.2%
2017 CWE-399 1 PoC

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacke

CVE-2025-2277
Server Networking
7.5
HIGH
EPSS
0.2%
2025 CWE-200 1 PoC

Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.

CVE-2025-47913
golang.org/x/crypto/ssh/agent Networking
7.5
HIGH
EPSS
0.0%
2025 1 PoC

SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.

CVE-2025-60694
Software Genérico Web Networking
7.5
HIGH
EPSS
2.8%
2025 2 PoCs

A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function improperly concatenates user-supplied CGI parameters (route_ipaddr_0~3, route_netmask_0~3, route_gateway_0~3) into fixed-size buffers (v6, v10, v14) without proper bounds checking. Remote attackers can exploit this vulnerability via specially crafted HTTP requests to execute arbitrary code or cause denial of service without authentication.

CVE-2025-31137
react-router Networking
7.5
HIGH
EPSS
0.1%
2025 CWE-444 1 PoC

React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability in Remix/React Router that affects all Remix 2 and React Router 7 consumers using the Express adapter. Basically, this vulnerability allows anyone to spoof the URL used in an incoming Request by putting a URL pathname in the port section of a URL that is part of a Host or X-Forwarded-Host header sent to a Remix/React Router request handler. This issue has been patched and released in Remix 2.16.3 and React Router 7.4.1.

CVE-2025-59370
Router Networking
7.5
HIGH
EPSS
0.3%
2025 CWE-78 1 PoC

A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.