Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.49% | — | Totolink N600r Firmware | 22/10/2025 | 17/6/2026 | TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Analizada | Alta (7.4) | 1.0% | — | Totolink N600r Firmware | 8/10/2025 | 17/6/2026 | A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the component HTTP Request Handler. Such manipulation of the argument wepkey leads to buffer overflow. It is possible to launch the attack… | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X18 Firmware | 1/10/2025 | 17/6/2026 | TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function. | |
| Modificada | Crítica (9.8) | 1.0% | — | Totolink X18 Firmware | 1/10/2025 | 17/6/2026 | TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function. | |
| Analizada | Crítica (9.3) | 1.3% | — | Totolink X6000r Firmware | 25/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708. | |
| Analizada | Media (5.3) | 0.39% | — | Totolink N600r Firmware | 25/9/2025 | 17/6/2026 | A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service. | |
| Analizada | Alta (7.3) | 0.85% | — | Totolink X6000r Firmware | 24/9/2025 | 17/6/2026 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207. | |
| Analizada | Crítica (9.3) | 13% | — | Totolink X6000r Firmware | 24/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1360_B20241207. | |
| Analizada | Alta (7) | 8.1% | — | Totolink X6000r Firmware | 23/9/2025 | 17/6/2026 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207. | |
| Analizada | Crítica (9.8) | 4.4% | — | Totolink X6000r Firmware | 15/9/2025 | 17/6/2026 | TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request. | |
| Analizada | Alta (8) | 0.61% | — | Totolink X2000r Firmware | 12/9/2025 | 17/6/2026 | An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password | |
| Analizada | Media (5.5) | 3.0% | — | Totolink N600r Firmware | 4/9/2025 | 17/6/2026 | A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi-bin/cstecgi.cgi. Executing manipulation can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (2.1) | 3.7% | — | Totolink X5000r Firmware | 4/9/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the file /boafrm/formParentControl. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of the file /boafrm/formOneKeyAccessButton. Performing manipulation of the argument submit-url results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and… | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file /boafrm/formFilter. Such manipulation of the argument ip6addr leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this issue is the function sub_419BE0 of the file /boafrm/formIpQoS. This manipulation of the argument mac causes buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_4162DC of the file /boafrm/formFilter. The manipulation of the argument ip6addr results in buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Analizada | Baja (1.1) | 0.21% | — | Totolink X2000r Firmware | 28/8/2025 | 25/7/2026 | A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly… | |
| Analizada | Media (5.5) | 11% | — | Totolink T10 Firmware | 27/8/2025 | 17/6/2026 | A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (7.4) | 0.85% | — | Totolink A720r Firmware | 21/8/2025 | 17/6/2026 | A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument desc results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to… | |
| Analizada | Crítica (9.8) | 7.6% | — | Totolink A3002r Firmware | 18/8/2025 | 17/6/2026 | TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint. | |
| Analizada | Media (6.5) | 0.82% | — | Totolink A3002r Firmware | 18/8/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html. | |
| Analizada | Media (6.5) | 1.1% | — | Totolink A3002r Firmware | 18/8/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice. | |
| Analizada | Alta (7.5) | 0.40% | — | Totolink A3002r Firmware | 18/8/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. |