Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 3.7% | — | Totolink Nr1800x Firmware | 29/3/2026 | 17/6/2026 | A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 3.7% | — | Totolink A3600r Firmware | 29/3/2026 | 17/6/2026 | A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument NoticeUrl results in command injection. The attack may be launched remotely. The exploit is… | |
| Analizada | Alta (7.4) | 1.0% | — | Totolink Lr350 Firmware | 27/3/2026 | 17/6/2026 | A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (8.6) | 5.3% | — | Totolink X6000r Firmware | 23/3/2026 | 17/6/2026 | A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely. | |
| Analizada | Media (5.5) | 2.9% | — | Totolink Wa300 Firmware | 20/3/2026 | 17/6/2026 | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 3.0% | — | Totolink N300rh Firmware | 8/3/2026 | 17/6/2026 | A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation results in os command injection. The attack can be initiated remotely. The exploit has been made public and… | |
| Analizada | Alta (8.9) | 4.5% | — | Totolink N300rh Firmware | 27/2/2026 | 17/6/2026 | A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be… | |
| Modificada | Alta (7.5) | 0.35% | 💥 PoC | Totolink X5000r Firmware | 24/2/2026 | 5/7/2026 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1) without sufficient bounds checking. When lighttpd s request size limit is not enforced, a crafted… | |
| Analizada | Alta (8.8) | 1.8% | — | Totolink X6000r Firmware | 23/2/2026 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to a date -s shell command through CsteSystem. While the first two tokens of the input are validated,… | |
| Analizada | Crítica (9.8) | 0.72% | — | Totolink X5000r Firmware | 23/2/2026 | 17/6/2026 | TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through CsteSystem without validating if the input starts with a hyphen (-). This allows… | |
| Analizada | Alta (8) | 3.3% | — | Totolink X5000r Firmware | 23/2/2026 | 17/6/2026 | TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without adequate validation or filtering. This… | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink A3002ru Firmware | 17/2/2026 | 17/6/2026 | TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function. | |
| Modificada | Alta (8.8) | 1.0% | — | Totolink A3002ru Firmware | 17/2/2026 | 17/6/2026 | TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter function. | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink A3002ru Firmware | 17/2/2026 | 21/9/2026 | TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function. | |
| Analizada | Baja (2.1) | 2.6% | — | Totolink Wa300 Firmware | 8/2/2026 | 17/6/2026 | A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Ipaddr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Analizada | Media (6.5) | 0.46% | — | Totolink A950rg Firmware | 3/2/2026 | 17/6/2026 | A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The urlKeyword parameter is not properly validated, and the function concatenates multiple user-controlled fields into a fixed-size stack buffer without performing boundary checks. A remote attacker can… | |
| Analizada | Crítica (9.8) | 0.69% | — | Totolink A950rg Firmware | 3/2/2026 | 17/6/2026 | A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg interface of the /lib/cste_modules/ipv6.so module. The function fails to properly validate the length of the user-controlled radvdinterfacename parameter, allowing remote attackers to trigger a stack… | |
| Analizada | Crítica (9.8) | 0.51% | — | Totolink A950rg Firmware | 3/2/2026 | 17/6/2026 | A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists in the setIpQosRules interface of /lib/cste_modules/firewall.so where the comment parameter is not properly validated for length. | |
| Analizada | Crítica (9.8) | 0.81% | — | Totolink A950rg Firmware | 3/2/2026 | 17/6/2026 | TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /lib/cste_modules/firewall.so. The vulnerability occurs because the `url` parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to… | |
| Aplazada | Crítica (9.2) | 1.0% | — | Totolink X6000rAI | 30/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1498_B20250826. | |
| Analizada | Alta (7.4) | 0.76% | — | Totolink A3600r Firmware | 30/1/2026 | 17/6/2026 | A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. Performing a manipulation of the argument apcliSsid results in buffer overflow. It is possible to initiate the attack remotely. The exploit has been released… | |
| Analizada | Baja (2.1) | 2.4% | — | Totolink A7000r Firmware | 29/1/2026 | 17/6/2026 | A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Analizada | Baja (2.1) | 2.2% | — | Totolink A7000r Firmware | 29/1/2026 | 17/6/2026 | A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument FileName can lead to command injection. The attack can be launched remotely. The exploit has been made available to the public… | |
| Analizada | Baja (2.1) | 3.5% | — | Totolink A7000r Firmware | 28/1/2026 | 17/6/2026 | A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument url causes command injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 3.1% | — | Totolink A7000r Firmware | 28/1/2026 | 17/6/2026 | A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. |