Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
1440 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 0.22% | — | Totolink A720r Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file using fgets() into a local buffer and subsequently parses the line using sscanf() into a single-byte variable with the %s format specifier.… | |
| Modificada | Media (6.5) | 0.52% | — | Totolink Lr1200gb FirmwareTotolink Nr1800x Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings using sprintf() into fixed-size stack… | |
| Modificada | Media (6.5) | 1.0% | — | Totolink A720r Firmware | 13/11/2025 | 5/7/2026 | A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handles network interface reinitialization from '/var/system/linux_vlan_reinit'. Input is only partially validated by checking the prefix of… | |
| Modificada | Media (6.5) | 1.5% | — | Totolink A720r Firmware | 13/11/2025 | 5/7/2026 | A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed… | |
| Analizada | Alta (7.5) | 0.37% | — | Totolink A7000r Firmware | 10/11/2025 | 17/6/2026 | Se descubrió que TOTOLink A7000R V9.1.0u.6115_B20201022 contenía un desbordamiento de pila en el parámetro addEffect de la función urldecode. Esta vulnerabilidad permite a los atacantes causar una Denegación de Servicio (DoS) mediante una solicitud POST manipulada. | |
| Analizada | Alta (7.5) | 0.37% | — | Totolink A7000r Firmware | 10/11/2025 | 17/6/2026 | TOTOLink A7000R V9.1.0u.6115_B20201022 se descubrió que contenía un desbordamiento de pila en el parámetro ssid de la función urldecode. Esta vulnerabilidad permite a los atacantes causar una Denegación de Servicio (DoS) mediante una solicitud manipulada. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink A7000r Firmware | 31/10/2025 | 17/6/2026 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink A7000r Firmware | 31/10/2025 | 17/6/2026 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink A7000r Firmware | 31/10/2025 | 17/6/2026 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink A7000r Firmware | 31/10/2025 | 17/6/2026 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.4) | 1.0% | — | Totolink A3300r Firmware | 27/10/2025 | 8/10/2026 | Una vulnerabilidad ha sido encontrada en TOTOLINK A3300R 17.0.0cu.557_B20221024. El elemento afectado es la función setSyslogCfg del archivo /cgi-bin/cstecgi.cgi del componente Gestor de Parámetros POST. Dicha manipulación del argumento enable conduce a un desbordamiento de búfer basado en pila. Es posible lanzar el… | |
| Analizada | Alta (7.4) | 1.0% | — | Totolink A3300r Firmware | 27/10/2025 | 8/10/2026 | Se ha encontrado un fallo en TOTOLINK A3300R 17.0.0cu.557_B20221024. El elemento afectado es la función setScheduleCfg del archivo /cgi-bin/cstecgi.cgi del componente Gestor de Parámetros POST. Esta manipulación del argumento recHour causa desbordamiento de búfer basado en pila. Es posible iniciar el ataque… | |
| Analizada | Alta (8.7) | 1.0% | — | Totolink A3300r Firmware | 27/10/2025 | 8/10/2026 | Una vulnerabilidad fue detectada en TOTOLINK A3300R 17.0.0cu.557_B20221024. Se ve afectada la función setOpModeCfg del archivo /cgi-bin/cstecgi.cg del componente Gestor de Parámetros POST. La manipulación del argumento opmode resulta en desbordamiento de búfer basado en pila. El ataque puede realizarse desde remoto. | |
| Analizada | Alta (7.4) | 1.0% | — | Totolink A3300r Firmware | 27/10/2025 | 8/10/2026 | Se detectó una vulnerabilidad en TOTOLINK A3300R 17.0.0cu.557_B20221024. Esto afecta a la función setLanguageCfg del archivo /cgi-bin/cstecgi.cgi del componente Gestor de Parámetros POST. La manipulación del argumento lang resulta en desbordamiento de búfer basado en pila. Es posible lanzar el ataque remotamente. El… | |
| Analizada | Alta (7.4) | 0.84% | — | Totolink A3300r Firmware | 27/10/2025 | 8/10/2026 | Se ha detectado una vulnerabilidad de seguridad en TOTOLINK A3300R 17.0.0cu.557_B20221024. Esto afecta a la función setDmzCfg del archivo /cgi-bin/cstecgi.cgi. La manipulación del argumento ip conduce a un desbordamiento de búfer. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado públicamente y… | |
| Analizada | Alta (7.4) | 0.84% | — | Totolink A3300r Firmware | 27/10/2025 | 8/10/2026 | Se ha identificado una debilidad en TOTOLINK A3300R 17.0.0cu.557_B20221024. El elemento afectado es la función setDdnsCfg del archivo /cgi-bin/cstecgi.cgi. La ejecución de manipulación puede conducir a un desbordamiento de búfer. El ataque puede realizarse de forma remota. El exploit se ha puesto a disposición del… | |
| Analizada | Alta (7.5) | 1.8% | — | Totolink N600r Firmware | 22/10/2025 | 17/6/2026 | A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Analizada | Alta (7.5) | 2.1% | — | Totolink N600r Firmware | 22/10/2025 | 17/6/2026 | A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. |