Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Totolink A3700r Firmware | 11/1/2024 | 17/6/2026 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink A3700r Firmware | 11/1/2024 | 17/6/2026 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Totolink A3700r Firmware | 11/1/2024 | 17/6/2026 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setDiagnosisCfg function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Totolink A3700r Firmware | 11/1/2024 | 17/6/2026 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Totolink A3700r Firmware | 11/1/2024 | 17/6/2026 | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function. | |
| Modificada | Crítica (9.8) | 1.2% | — | Totolink A3700r Firmware | 22/12/2023 | 17/6/2026 | There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513. | |
| Modificada | Alta (7.8) | 0.35% | — | Totolink A3700r Firmware | 20/11/2023 | 9/7/2026 | An issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function. | |
| Modificada | Crítica (9.8) | 65% | 💥 Exploit | Totolink A3700r Firmware | 25/10/2023 | 17/6/2026 | An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function. | |
| Modificada | Crítica (9.8) | 0.79% | — | Totolink A3700r FirmwareTotolink N600r Firmware | 25/9/2023 | 9/7/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control. | |
| Modificada | Alta (7.8) | 0.33% | — | Totolink A3700r Firmware | 25/8/2022 | 17/6/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg. | |
| Modificada | Alta (7.8) | 0.35% | — | Totolink A3700r Firmware | 25/8/2022 | 17/6/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter. | |
| Modificada | Alta (7.8) | 0.35% | — | Totolink A3700r Firmware | 25/8/2022 | 17/6/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules. | |
| Modificada | Alta (7.8) | 0.34% | — | Totolink A3700r Firmware | 25/8/2022 | 17/6/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg. | |
| Modificada | Alta (7.8) | 0.33% | — | Totolink A3700r Firmware | 25/8/2022 | 17/6/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg. | |
| Modificada | Alta (7.8) | 1.2% | — | Totolink A3700r Firmware | 25/8/2022 | 17/6/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg. | |
| Modificada | Alta (7.8) | 1.0% | — | Totolink A3700r Firmware | 25/8/2022 | 17/6/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile. | |
| Modificada | Alta (7.8) | 1.0% | — | Totolink A3700r Firmware | 25/8/2022 | 17/6/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost. | |
| Modificada | Alta (7.8) | 1.0% | — | Totolink A3700r Firmware | 25/8/2022 | 17/6/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg. |