Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

43 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)1.0%—Totolink T8 Firmware22/8/202417/6/2026
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been declared as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to buffer overflow. The attack can be initiated remotely. NOTE: The vendor was contacted early about this disclosure but did not…
AnalizadaMedia (5.3)2.9%—Totolink T8 Firmware22/8/202417/6/2026
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. NOTE: The vendor was contacted early about this disclosure but did not…
AnalizadaAlta (8.7)0.80%—Totolink T8 Firmware22/8/202417/6/2026
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this issue is the function setDiagnosisCfg. The manipulation leads to buffer overflow. The attack may be launched remotely. NOTE: The vendor was contacted early about this disclosure but did not respond in any…
AnalizadaMedia (5.3)1.9%—Totolink T8 Firmware22/8/202417/6/2026
A vulnerability has been found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg. The manipulation leads to os command injection. The attack can be launched remotely. NOTE: The vendor was contacted early about this disclosure but did…
ModificadaMedia (5.3)1.5%—Totolink T8 Firmware26/1/202417/6/2026
A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The…
ModificadaMedia (5.3)0.95%—Totolink T8 Firmware16/1/202417/6/2026
A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack…
ModificadaCrítica (9.8)2.1%—Totolink T8 Firmware3/2/202317/6/2026
A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
ModificadaCrítica (9.8)2.1%—Totolink T8 Firmware3/2/202317/6/2026
A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
ModificadaCrítica (9.8)0.89%—Totolink T8 Firmware3/2/202317/6/2026
TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.
ModificadaCrítica (9.8)1.9%—Totolink T8 Firmware3/2/202317/6/2026
TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.
ModificadaCrítica (9.8)2.1%—Totolink T8 Firmware3/2/202317/6/2026
A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
ModificadaCrítica (9.8)2.1%—Totolink T8 Firmware3/2/202317/6/2026
A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
ModificadaCrítica (9.8)2.1%—Totolink T8 Firmware3/2/202317/6/2026
A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
ModificadaCrítica (9.8)2.1%—Totolink T8 Firmware3/2/202317/6/2026
A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.
ModificadaCrítica (9.8)1.4%—AsuswrtAsuswrt-merlin NEW GENAsus XT8 FirmwareAsus Tuf-ax3000 V2 Firmware+155/8/202217/6/2026
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
ModificadaCrítica (9)0.98%—Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+895/7/202217/6/2026
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
ModificadaMedia (6.8)0.43%—GE Vivid E95 FirmwareGE Vivid E90 FirmwareGE Vivid S70n FirmwareGE Vivid T8 Firmware+1220/2/202017/6/2026
A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products:…
ModificadaMedia (4.6)0.40%—Stm32f071rb FirmwareStm32f071v8 FirmwareStm32f071vb FirmwareStm32f072c8 Firmware+6812/9/201817/6/2026
Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wire Debug (SWD) commands because there is a race condition between full initialization of the SWD interface and the setup…