Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en TOTOLINK N600R 4.3.0cu.7647_B20210106
Se ha identificado una vulnerabilidad de desbordamiento de búfer en pila (stack-based buffer overflow) en el controlador CGI del router TOTOLINK N600R versión 4.3.0cu.7647_B20210106. La falla reside en la función setSystemConfig del archivo /cgi-bin/cstecgi.cgi y puede ser explotada remotamente manipulando el parámetro Hostname. Con CVSS 10.0, esta vulnerabilidad permite ejecución de código remoto sin autenticación y afecta a equipos de red en empresas, ISPs y centros de datos en toda Latinoamérica.
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76071] Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that al…
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verif…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76070] Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that al…
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote cod…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-78169] A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the functio…
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
M Crítico vulnerabilidad
23/08/2026
Desbordamiento de búfer en Comfast CF-N1-S 2.6.0 permite ejecución remota de código
Se identificó una vulnerabilidad crítica (CVSS 9.9) en enrutadores Comfast CF-N1-S versión 2.6.0.1 en el componente de administración web. Un atacante remoto puede explotar un desbordamiento de búfer en la pila mediante manipulación de los parámetros timestr/ntp_client_enabled en la función /cgi-bin/mbox-config para ejecutar código arbitrario. El exploit es público y activamente utilizado en ataques.
M Crítico vulnerabilidad
22/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en TRENDnet TEW-821DAP 2.2.01b05
Se identificó una vulnerabilidad de severidad crítica (CVSS 10.0) en el manejador de configuración NTP del dispositivo TRENDnet TEW-821DAP versión 2.2.01b05. Un atacante puede manipular parámetros de zona horaria y servidores NTP a través del archivo /cgi-bin/apply_time.cgi para provocar un desbordamiento de búfer en la pila de memoria. Esta vulnerabilidad afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan estos enrutadores/puntos de acceso en infraestructuras de red crítica sin internet directo.
M Crítico vulnerabilidad
20/08/2026
[CVE-2026-77148] A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the fi…
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
20/08/2026
[CVE-2026-77022] A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the functi…
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks…
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-76589] A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 …
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-76590] A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some …
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-76584] A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some…
A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-16885] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-16872] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-16687] IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and …
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing arbitrary code execution, giving the attacker full control over the managed system, resulting in a confidentiality, inte…
M Crítico vulnerabilidad
19/08/2026
Vulnerabilidad crítica en Comfast CF-N1-S 2.6.0.1 permite desbordamiento de búfer remoto
Se ha identificado una falla de seguridad crítica (CVSS 10.0) en el dispositivo Comfast CF-N1-S versión 2.6.0.1 que afecta el procesamiento de parámetros URI en /cgi-bin/mbox-config. Un atacante remoto puede explotar un desbordamiento de búfer en la pila mediante manipulación de los parámetros width/height, comprometiendo completamente la integridad del dispositivo. Empresas en LATAM que utilicen estos puntos de acceso inalámbricos en infraestructura de oficinas o datos están en riesgo inmediato de intrusión no autorizada.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
19/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en UTT HiPER 1200GW hasta versión 2.5.3-170306
Se ha identificado una debilidad en los equipos UTT HiPER 1200GW (versiones hasta 2.5.3-170306) que permite un desbordamiento de búfer basado en pila mediante manipulación remota del parámetro 'timestart' en la función strcpy del archivo /goform/formGroupConfig. Con puntuación CVSS 9.9, este dispositivo ampliamente utilizado en redes corporativas de LATAM como gateway de seguridad es vulnerable a ejecución remota de código. El exploit está disponible públicamente, elevando significativamente el riesgo de compromiso.
M Crítico vulnerabilidad
19/08/2026
Vulnerabilidad crítica en UTT HiPER 1250GW permite ejecución remota de código (CVE-2026-76004)
Se ha identificado una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en UTT HiPER 1250GW versiones hasta 3.2.7-210907-180535. El fallo existe en el manejador HTTP del formulario /goform/aspApBasicConfigUrcp y puede ser explotado remotialmente sin autenticación manipulando el parámetro pvid. El exploit está públicamente disponible, poniendo en riesgo crítico los equipos desplegados en infraestructuras de ISPs, centros de datos y operadores de telecomunicaciones en América Latina.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-75976] A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of …
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75877] A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function Syst…
A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/FUN_0043372C of the component alphapd. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75784] A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the functio…
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.