Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "D-Link" — 43 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82692] A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown par…
A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
31/08/2026
Inyección de comandos OS crítica en NAS D-Link DNS-320L, DNS-327L, DNS-340L y DNS-345
Se ha identificado una vulnerabilidad crítica (CVSS 9.1) en dispositivos NAS D-Link que permite inyección de comandos del sistema operativo a través del parámetro f_ups_ip en el manejador CGI /cgi-bin/usb_device.cgi. La explotación es remota, sin autenticación requerida, y el exploit público ya circula. Afecta modelos hasta la versión 20260717, comprometiendo la integridad de servidores de almacenamiento en infraestructuras PYME y empresariales de LATAM.
M Crítico vulnerabilidad
31/08/2026
Vulnerabilidad crítica en dispositivos D-Link DNS (320L, 327L, 340L, 345) permite inyección de comandos
Se detectó una vulnerabilidad crítica (CVSS 9.9) en los manejadores ISO de dispositivos de almacenamiento en red D-Link afectados hasta la versión 20260717. Un atacante remoto puede ejecutar comandos del sistema operativo a través del parámetro upIsoRootPath en /cgi-bin/isomount_mgr.cgi, comprometiendo completamente la integridad y confidencialidad de datos almacenados. El exploit está públicamente disponible y es explotable sin autenticación.
M Crítico vulnerabilidad
31/08/2026
Inyección de comandos OS crítica en dispositivos D-Link DNS-327L y DNS-340L (CVE-2026-82690)
Se ha identificado una vulnerabilidad de inyección de comandos del sistema operativo en routers D-Link DNS-327L y DNS-340L hasta la versión 20260717, accesible remotamente a través del parámetro f_dev en /cgi-bin/ve_mgr.cgi. Con puntuación CVSS de 9.1, este defecto permite a atacantes ejecutar comandos arbitrarios sin autenticación. El exploit público amplifica el riesgo para empresas y proveedores de conectividad en Latinoamérica que utilizan estos dispositivos en sus infraestructuras de red.
M Crítico vulnerabilidad
31/08/2026
Vulnerabilidad crítica de inyección de comandos en almacenamiento NAS D-Link DNS-340L/345
Se ha detectado una vulnerabilidad crítica (CVSS 9.1) en los dispositivos NAS D-Link DNS-340L y DNS-345 que permite inyección de comandos del sistema operativo a través del componente Virtual Volume Handler (/cgi-bin/virtual_vol.cgi). Un atacante remoto puede manipular los parámetros f_sharename, f_target o f_name para ejecutar comandos arbitrarios. Esta vulnerabilidad afecta las versiones 1.01B04, 1.03B06, 1.04B02 y 1.05b04, representando riesgo crítico para infraestructuras de almacenamiento en empresas mexicanas y latinoamericanas.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82593] A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /bo…
A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.
M Crítico vulnerabilidad
30/08/2026
[CVE-2026-82592] A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the f…
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71956] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71957] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71958] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71954] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71955] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71948] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71949] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71950] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71951] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71952] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71953] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71944] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71945] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.