Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101076] A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the f…
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101075] A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the…
A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about thi…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101072] A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system …
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101007] A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputS…
A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101008] A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file o…
A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted ear…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101009] A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function p…
A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendo…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101002] A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function …
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101001] A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval…
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-100896] A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the funct…
A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
25/09/2026
[CVE-2025-51457] D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within t…
D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can exploit some parameters to execute arbitrary system commands.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65111] NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an at…
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
M Alto vulnerabilidad
21/09/2026
Inyección de comandos alta en Router Feiyu Star B-MB5E202 afecta infraestructura de red
Se identificó una vulnerabilidad de inyección de comandos (CVSS 7.4) en el Router Feiyu Star modelo B-MB5E202-210322-r11656 de Chengdu Feiyuxing Technology. El fallo está en el manejador de cookies del archivo /send_order.cgi, donde la manipulación del parámetro session_id permite ejecución remota de comandos sin autenticación. Empresas en México y Latinoamérica que utilicen este equipo en perímetros de red enfrentan riesgo inmediato de compromiso total.
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94098] A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unk…
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94099] A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some u…
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was c…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94095] A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability…
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacte…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94096] A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unkn…
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this d…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94097] A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part o…
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about t…
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-93958] A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function syst…
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de inyección de comandos en Totolik A3002MU
Se ha identificado una debilidad en el enrutador Totolik A3002MU versión Hh-B20211125.1046 que permite inyección de comandos remotos a través del parámetro localPin en la función formWsc del archivo /boafrm/formWsc. La vulnerabilidad tiene puntuación CVSS 9.9 (crítica) y ya cuenta con exploits públicamente disponibles, exponiendo a empresas en LATAM que utilizan este dispositivo a acceso no autorizado e infiltración de redes.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-88622] NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.