Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A7100ruAI | 9/4/2026 | 17/6/2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wifiOff can lead to os command injection. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A7100ruAI | 9/4/2026 | 17/6/2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sambaEnabled results in os command injection. It is possible to initiate the attack remotely.… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A7100ruAI | 9/4/2026 | 17/6/2026 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument wanIdx leads to os command injection. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A7100ruAI | 9/4/2026 | 17/6/2026 | A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument merge results in os command injection. It is possible to initiate the attack remotely.… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A7100ruAI | 9/4/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument addrPrefixLen leads to os command injection. The attack may be performed… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A7100ruAI | 9/4/2026 | 17/6/2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes os command injection. The attack is possible to be carried out remotely. The exploit has been made… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A7100ruAI | 9/4/2026 | 17/6/2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be executed remotely. The exploit has been released… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A7100ruAI | 9/4/2026 | 17/6/2026 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is… | |
| Aplazada | Media (5.5) | 2.1% | — | Totolink A7100ruAI | 7/4/2026 | 24/7/2026 | A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 2.1% | — | Totolink A7100ruAI | 6/4/2026 | 24/7/2026 | A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument firewallType leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 2.1% | — | Totolink A7100ruAI | 6/4/2026 | 24/7/2026 | A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 2.1% | — | Totolink A7100ruAI | 6/4/2026 | 24/7/2026 | A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument tz results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 2.1% | — | Totolink A7100ruAI | 6/4/2026 | 24/7/2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (5.5) | 2.1% | — | Totolink A7100ruAI | 6/4/2026 | 24/7/2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. The exploit has been made available to the… | |
| Aplazada | Media (5.5) | 2.1% | — | Totolink A7100ruAI | 6/4/2026 | 20/7/2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument resetFlags results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and… | |
| Modificada | Crítica (9.8) | 0.34% | — | Totolink A7100ru FirmwareTotolink A950rg FirmwareTotolink T10 Firmware | 21/7/2025 | 5/7/2026 | In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks. | |
| Modificada | Crítica (9.8) | 14% | — | Totolink A7100ru Firmware | 25/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag leads to buffer overflow. The attack… | |
| Modificada | Crítica (9.8) | 1.8% | — | Totolink A7100ru Firmware | 18/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Totolink A7100RU 7.4cu.2313_B20191024. Affected is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag with the input ie8 leads to buffer overflow. It is… | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink A7100ru Firmware | 7/6/2023 | 17/6/2026 | TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg. | |
| Modificada | Crítica (9.8) | 2.1% | — | Totolink A7100ru Firmware | 5/5/2023 | 17/6/2026 | TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload. | |
| Modificada | Crítica (9.8) | 2.1% | — | Totolink A7100ru Firmware | 5/5/2023 | 17/6/2026 | TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink A7100ru Firmware | 7/4/2023 | 17/6/2026 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink A7100ru Firmware | 7/4/2023 | 17/6/2026 | TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink A7100ru Firmware | 28/3/2023 | 17/6/2026 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink A7100ru Firmware | 28/3/2023 | 17/6/2026 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg. |