Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93739] A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function form…
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93740] A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formW…
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93738] A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSched…
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91003] A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the …
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91001] A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of t…
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en D-Link DIR-878 120B05 permite desbordamiento de búfer remoto
Se ha identificado un fallo de seguridad crítico (CVSS 9.9) en el enrutador D-Link DIR-878 versión 120B05 que afecta la función SetWan3Settings. Un atacante remoto puede explotar un desbordamiento de búfer en la pila manipulando los parámetros de DNS primario/secundario, comprometiendo completamente dispositivos expuestos en redes corporativas y pequeña empresa de México y LATAM.
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en router D-Link DIR-878 120B05 permite desbordamiento de pila remoto
Se detectó una vulnerabilidad crítica (CVSS 9.9) en el router D-Link DIR-878 versión 120B05 que afecta la función SetDynamicDNSIPv6Settings. Un atacante remoto puede explotar esta falla manipulando los parámetros IPv6Address/Hostname para provocar un desbordamiento de pila (stack-based buffer overflow), potencialmente logrando ejecución remota de código. Este router es ampliamente utilizado en pequeñas y medianas empresas (PyMES) en México y LATAM para conectividad WAN.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90680] A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is th…
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90608] A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function fo…
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90607] A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNew…
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90605] A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the…
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90606] A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects…
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-87931] A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearabl…
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-86510] A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params …
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-86509] A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of t…
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
07/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en D-Link DIR-822A A_101
Se ha identificado una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en el componente udhcpcd del router D-Link DIR-822A versión A_101, específicamente en la función strcpy del archivo udhcpcd/serverpacket.c. Esta falla puede ser explotada remotamente sin autenticación, permitiendo a atacantes ejecutar código arbitrario con privilegios del dispositivo. El exploit se encuentra públicamente disponible y actualmente es explotable en infraestructuras de empresas en México y LATAM que utilicen este modelo de router.
M Crítico vulnerabilidad
06/09/2026
CVE-2026-86165: Vulnerabilidad crítica de desbordamiento de búfer en Tenda HG10 300001138
Se identificó una vulnerabilidad de desbordamiento de búfer (buffer overflow) en el router Tenda HG10 modelo 300001138, específicamente en la función formURL del archivo /boaform/admin/formURL. Un atacante remoto puede manipular los parámetros Keywd/urlFQDN para ejecutar código arbitrario sin autenticación previa. El exploit es público y activamente explotado en la región LATAM, afectando principalmente a PyMEs con infraestructura de redes domésticas y pequeñas oficinas.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85109] A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of…
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85031] A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of th…
A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82616] A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUpl…
A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.