Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Crítico vulnerabilidad
09/08/2026
Vulnerabilidad crítica de inyección de comandos en router MSI Radix AXE6600 (CVE-2026-71985)
El firmware v781521 del router MSI Radix AXE6600 contiene una vulnerabilidad de inyección de comandos en la función de control de acceso que permite a atacantes remotos ejecutar comandos arbitrarios y obtener privilegios root. Esta vulnerabilidad afecta principalmente a empresas y usuarios en LATAM que utilizan estos dispositivos como puntos de acceso críticos en infraestructuras de red corporativas e ISP.
M Crítico vulnerabilidad
09/08/2026
Vulnerabilidad crítica de inyección de comandos en router MSI Radix AXE6600 (CVE-2026-71986)
El firmware v781521 del router MSI Radix AXE6600 contiene una vulnerabilidad de inyección de comandos en la función DMZ que permite a atacantes remotos ejecutar comandos arbitrarios y obtener privilegios de root. Esta vulnerabilidad afecta directamente a pequeñas y medianas empresas en LATAM que utilizan este equipo como puerta de enlace de red, exponiendo la infraestructura interna a compromisos graves sin necesidad de autenticación.
M Crítico vulnerabilidad
09/08/2026
[CVE-2026-71987] MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the …
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
M Crítico vulnerabilidad
09/08/2026
Vulnerabilidad crítica de inyección de comandos en router MSI Radix AXE6600 (CVE-2026-71988)
El router MSI Radix AXE6600 versión de firmware v781521 contiene una vulnerabilidad de inyección de comandos en la función portFw que permite a atacantes remotos ejecutar comandos arbitrarios y obtener privilegios root. Esta vulnerabilidad afecta principalmente a PyMEs y empresas con infraestructura de red basada en equipos de consumo de gama media, comprometiendo la integridad de redes corporativas en México y LATAM. El CVSS 9.8 indica riesgo crítico sin requerir autenticación previa.
M Crítico vulnerabilidad
09/08/2026
[CVE-2026-71989] MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the …
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71983] MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the …
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71956] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71957] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71958] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71954] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71955] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71948] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71949] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71950] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71951] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71952] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71953] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71944] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71945] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71946] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.