Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Totolink Ex1200t Firmware | 3/6/2022 | 17/6/2026 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink Ex1200t Firmware | 3/6/2022 | 17/6/2026 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack. | |
| Modificada | Alta (7.5) | 1.4% | — | Totolink Ex1200t Firmware | 3/6/2022 | 17/6/2026 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink Ex1200t Firmware | 3/6/2022 | 17/6/2026 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack. | |
| Modificada | Crítica (9.8) | 44% | 💥 Exploit | Totolink Ex1200t Firmware | 3/6/2022 | 17/6/2026 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. | |
| Modificada | Alta (7.5) | 2.1% | — | Totolink Ex1200t Firmware | 3/6/2022 | 17/6/2026 | TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file. | |
| Modificada | Crítica (9.8) | 2.4% | — | Totolink Ex1200t Firmware | 3/6/2022 | 17/6/2026 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can control deviceName to attack. | |
| Modificada | Crítica (9.8) | 2.4% | — | Totolink Ex1200t Firmware | 3/6/2022 | 17/6/2026 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control thedeviceName to attack. | |
| Modificada | Alta (7.5) | 1.7% | — | Totolink Ex1200t Firmware | 2/6/2022 | 9/7/2026 | TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system. | |
| Modificada | Crítica (9.8) | 4.4% | — | Totolink Ex1200t Firmware | 2/6/2022 | 9/7/2026 | TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin. | |
| Modificada | Crítica (9.8) | 6.6% | — | Totolink Ex1200t Firmware | 2/6/2022 | 9/7/2026 | TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code. | |
| Modificada | Alta (8.8) | 4.4% | — | Totolink Ex300 V2 FirmwareTotolink Ex1200t Firmware | 30/3/2022 | 17/6/2026 | totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism. |