Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.81% | — | Totolink A702r FirmwareTotolink A3002r FirmwareTotolink A3002ru Firmware | 17/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.… | |
| Analizada | Alta (8.7) | 0.81% | — | Totolink A702r FirmwareTotolink A3002r FirmwareTotolink A3002ru Firmware | 17/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated… | |
| Analizada | Alta (8.7) | 0.81% | — | Totolink A702r FirmwareTotolink A3002r FirmwareTotolink A3002ru Firmware | 17/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the… | |
| Analizada | Alta (8.7) | 0.81% | — | Totolink A702r FirmwareTotolink A3002r FirmwareTotolink A3002ru Firmware | 17/5/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is the function submit-url of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack may be… | |
| Analizada | Alta (8.7) | 0.81% | — | Totolink A3002r FirmwareTotolink A3002ru Firmware | 16/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack may be… | |
| Analizada | Alta (8.7) | 0.81% | — | Totolink A3002r FirmwareTotolink A3002ru Firmware | 16/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument ip6addr leads to buffer overflow. The attack can be initiated… | |
| Analizada | Alta (8.7) | 0.81% | — | Totolink A3002r FirmwareTotolink A3002ru Firmware | 16/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type/ip_subnet leads to buffer overflow. It is possible to initiate… | |
| Analizada | Alta (8.7) | 0.81% | — | Totolink A3002r FirmwareTotolink A3002ru Firmware | 16/5/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel of the component HTTP POST Request Handler. The manipulation of the argument devicemac1 leads to buffer overflow. The attack… | |
| Analizada | Media (5.3) | 1.2% | — | Totolink A3002r FirmwareTotolink A3002ru Firmware | 16/5/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to command… | |
| Analizada | Crítica (9.8) | 0.60% | — | Totolink A3002r Firmware | 13/5/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface. | |
| Analizada | Crítica (9.8) | 0.60% | — | Totolink A3002r Firmware | 13/5/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface. | |
| Analizada | Crítica (9.8) | 0.60% | — | Totolink A3002r Firmware | 13/5/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface. | |
| Analizada | Crítica (9.8) | 11% | — | Totolink A3002r Firmware | 13/5/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function. | |
| Analizada | Media (5.4) | 4.9% | — | Totolink A3002r Firmware | 13/5/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface. | |
| Analizada | Media (5.4) | 0.35% | — | Totolink A3002r Firmware | 13/5/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface. | |
| Analizada | Media (5.4) | 4.9% | — | Totolink A3002r Firmware | 13/5/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface. | |
| Analizada | Media (5.4) | 5.0% | — | Totolink A3002r Firmware | 13/5/2025 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface. | |
| Analizada | Crítica (9.8) | 10% | — | Totolink A3002r Firmware | 28/3/2025 | 17/6/2026 | TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr. | |
| Analizada | Alta (8) | 0.42% | — | Totolink A3002r Firmware | 28/2/2025 | 17/6/2026 | TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa. | |
| Analizada | Alta (8) | 0.27% | — | Totolink A3002r Firmware | 28/2/2025 | 17/6/2026 | TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa. | |
| Analizada | Alta (8) | 0.27% | — | Totolink A3002r Firmware | 28/2/2025 | 17/6/2026 | TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa | |
| Analizada | Alta (8.8) | 1.1% | — | Totolink A3002r Firmware | 26/12/2024 | 17/6/2026 | TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc. | |
| Analizada | Crítica (9.8) | 0.94% | — | Totolink A3002r Firmware | 28/8/2024 | 17/6/2026 | TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversight leads to potential buffer overflow under specific circumstances. For instance,… | |
| Modificada | Crítica (9.8) | 0.63% | — | Totolink A3002r Firmware | 12/8/2024 | 17/6/2026 | TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl. | |
| Analizada | Alta (7.5) | 0.55% | — | Totolink A3002r Firmware | 1/5/2024 | 17/6/2026 | Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow. |