Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71930] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime functio…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71923] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set functi…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for th…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71924] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the …
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71925] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail funct…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for t…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71926] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice funct…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative cre…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71917] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace funct…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web m…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71918] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pathN, and valueN fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid admini…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71919] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot funct…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credenti…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71913] Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative creden…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71915] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus func…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credent…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71916] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable fu…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backticks, newline characters, and single quotes in the parameter field. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation req…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71906] Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. Th…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the devi…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71907] Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function.…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's we…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71908] Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_te…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administ…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71909] Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime functio…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web mana…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71910] Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the …
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71904] Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform fun…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid a…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71905] Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings func…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative cr…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-59561] Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulne…
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
M Alto vulnerabilidad
22/08/2026
[CVE-2026-57998] better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by inte…
better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A registry value containing shell metacharacters such as a semicolon, pipe, or command …