Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

61 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.81%—Totolink A702r FirmwareTotolink A3002r FirmwareTotolink A3002ru Firmware17/5/202517/6/2026
A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.…
AnalizadaAlta (8.7)0.81%—Totolink A702r FirmwareTotolink A3002r FirmwareTotolink A3002ru Firmware17/5/202517/6/2026
A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated…
AnalizadaAlta (8.7)0.81%—Totolink A702r FirmwareTotolink A3002r FirmwareTotolink A3002ru Firmware17/5/202517/6/2026
A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the…
AnalizadaAlta (8.7)0.81%—Totolink A702r FirmwareTotolink A3002r FirmwareTotolink A3002ru Firmware17/5/202517/6/2026
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is the function submit-url of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack may be…
AnalizadaAlta (8.7)0.81%—Totolink A3002r FirmwareTotolink A3002ru Firmware16/5/202517/6/2026
A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack may be…
AnalizadaAlta (8.7)0.81%—Totolink A3002r FirmwareTotolink A3002ru Firmware16/5/202517/6/2026
A vulnerability classified as critical was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument ip6addr leads to buffer overflow. The attack can be initiated…
AnalizadaAlta (8.7)0.81%—Totolink A3002r FirmwareTotolink A3002ru Firmware16/5/202517/6/2026
A vulnerability classified as critical has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type/ip_subnet leads to buffer overflow. It is possible to initiate…
AnalizadaAlta (8.7)0.81%—Totolink A3002r FirmwareTotolink A3002ru Firmware16/5/202517/6/2026
A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel of the component HTTP POST Request Handler. The manipulation of the argument devicemac1 leads to buffer overflow. The attack…
AnalizadaMedia (5.3)1.2%—Totolink A3002r FirmwareTotolink A3002ru Firmware16/5/202517/6/2026
A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to command…
AnalizadaCrítica (9.8)0.60%—Totolink A3002r Firmware13/5/202517/6/2026
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.
AnalizadaCrítica (9.8)0.60%—Totolink A3002r Firmware13/5/202517/6/2026
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.
AnalizadaCrítica (9.8)0.60%—Totolink A3002r Firmware13/5/202517/6/2026
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.
AnalizadaCrítica (9.8)11%—Totolink A3002r Firmware13/5/202517/6/2026
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.
AnalizadaMedia (5.4)4.9%—Totolink A3002r Firmware13/5/202517/6/2026
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.
AnalizadaMedia (5.4)0.35%—Totolink A3002r Firmware13/5/202517/6/2026
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.
AnalizadaMedia (5.4)4.9%—Totolink A3002r Firmware13/5/202517/6/2026
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.
AnalizadaMedia (5.4)5.0%—Totolink A3002r Firmware13/5/202517/6/2026
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.
AnalizadaCrítica (9.8)10%—Totolink A3002r Firmware28/3/202517/6/2026
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
AnalizadaAlta (8)0.42%—Totolink A3002r Firmware28/2/202517/6/2026
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.
AnalizadaAlta (8)0.27%—Totolink A3002r Firmware28/2/202517/6/2026
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.
AnalizadaAlta (8)0.27%—Totolink A3002r Firmware28/2/202517/6/2026
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa
AnalizadaAlta (8.8)1.1%—Totolink A3002r Firmware26/12/202417/6/2026
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
AnalizadaCrítica (9.8)0.94%—Totolink A3002r Firmware28/8/202417/6/2026
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversight leads to potential buffer overflow under specific circumstances. For instance,…
ModificadaCrítica (9.8)0.63%—Totolink A3002r Firmware12/8/202417/6/2026
TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.
AnalizadaAlta (7.5)0.55%—Totolink A3002r Firmware1/5/202417/6/2026
Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow.
Orbitaley — Vulnerabilidades