Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS runtime status via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS configuration, including domain, username, and password, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.51% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.33% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected client statistics via sending a crafted… | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 28/8/2026 | 2/9/2026 | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message. | |
| Aplazada | Media (4.3) | 0.33% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 2.3% | — | Lb-link Ac450mAI | 27/8/2026 | 8/9/2026 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit… | |
| Aplazada | Crítica (9.8) | 2.3% | — | Lb-link Router Ac2100 AZ3AI | 27/8/2026 | 8/9/2026 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can… | |
| Aplazada | Crítica (9.3) | 3.4% | — | Zbtlink We1326AIZbtlink We357AIZbtlink We5926AIZbtlink We5926 WDAI+12 | 27/8/2026 | 24/9/2026 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated… |