Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 24/5/2026 | 23/7/2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit is publicly… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 24/5/2026 | 23/7/2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument mode can lead to os command injection. It is possible to launch the attack… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 24/5/2026 | 23/7/2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument resetFlags results in os command injection. It is possible to initiate the… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 24/5/2026 | 23/7/2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument lang leads to os command injection. The attack may be performed from remote. The exploit is… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 24/5/2026 | 23/7/2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument command causes os command injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 24/5/2026 | 23/7/2026 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument ip results in os command injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink X5000rAI | 8/5/2026 | 17/6/2026 | A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 5/5/2026 | 17/6/2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument mac_address results in buffer overflow. The attack may be launched remotely. The exploit is… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink N300RH 3.2.4-B20220812. This affects the function setWanConfig of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument priDns leads to buffer overflow. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executing a manipulation of the argument FileName can lead to buffer overflow. The attack can be launched remotely. The exploit… | |
| Aplazada | Alta (8.9) | 1.0% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument Password results in buffer overflow. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink WA300 5.2cu.7112_B20190227. This affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument hostTime leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A weakness has been identified in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument langType causes command injection. Remote exploitation of the attack is possible. The… | |
| Aplazada | Alta (8.9) | 1.0% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument http_host results in buffer overflow. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A vulnerability was identified in Totolink WA300 5.2cu.7112_B20190227. Impacted is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument webWlanIdx leads to command injection. The attack may be initiated remotely. The exploit is publicly… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. This issue affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executing a manipulation of the argument File can lead to buffer overflow. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.53% | — | Totolink N300rhAI | 2/5/2026 | 17/6/2026 | A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Aplazada | Alta (7.4) | 2.9% | — | Totolink Nr1800xAI | 1/5/2026 | 17/6/2026 | A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Aplazada | Alta (8.9) | 1.0% | — | Totolink Nr1800xAILighttpdAI | 1/5/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 1/5/2026 | 17/6/2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument proto leads to os command injection. The attack may be initiated remotely. The exploit is publicly… | |
| Aplazada | Crítica (9.8) | 1.8% | — | Totolink N200reAI | 29/4/2026 | 17/6/2026 | TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function. | |
| Aplazada | Alta (7.5) | 0.46% | — | Totolink A3002ruAI | 29/4/2026 | 17/6/2026 | TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname parameter in the formMapDelDevice function. | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 28/4/2026 | 17/6/2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge results in os command injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 28/4/2026 | 17/6/2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument maxRtrAdvInterval leads to os command injection. It is possible to initiate the attack remotely. The… |