Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.34%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the sPort parameter at the addEffect function.
ModificadaAlta (7.8)1.0%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function setDiagnosisCfg.
ModificadaAlta (7.8)1.0%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the function NTPSyncWithHost.
ModificadaAlta (7.8)1.0%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.
ModificadaAlta (7.8)0.34%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command parameter at setting/setTracerouteCfg.
ModificadaAlta (7.8)1.2%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
ModificadaAlta (7.8)0.90%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at /setting/setLanguageCfg.
ModificadaAlta (7.8)0.34%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser parameter.
ModificadaAlta (7.8)1.0%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
ModificadaAlta (7.8)0.34%—Totolink A7000r Firmware25/8/202217/6/2026
TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
ModificadaCrítica (9.8)5.5%—Totolink X5000r FirmwareTotolink A7000r Firmware15/3/202217/6/2026
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
ModificadaCrítica (9.8)2.9%—Totolink X5000r FirmwareTotolink A7000r Firmware15/3/202217/6/2026
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
ModificadaCrítica (9.8)2.9%—Totolink X5000r FirmwareTotolink A7000r Firmware15/3/202217/6/2026
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.