Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg. | |
| Modificada | Alta (8.8) | 1.2% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg. | |
| Modificada | Alta (8.8) | 1.7% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg. | |
| Aplazada | Alta (8.6) | 0.21% | — | Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+7 | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions <… | |
| Analizada | Media (6.8) | 2.7% | — | Totolink X5000r Firmware | 13/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 13/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 13/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.7% | — | Totolink X5000r Firmware | 13/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Analizada | Alta (7.8) | 1.6% | — | Totolink X5000r Firmware | 13/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Analizada | Alta (8.8) | 1.7% | — | Totolink X5000r Firmware | 12/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.1% | — | Totolink X5000r Firmware | 12/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Analizada | Alta (8.8) | 1.7% | — | Totolink X5000r Firmware | 12/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 12/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUser. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 12/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 12/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.2% | — | Totolink X5000r Firmware | 12/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Analizada | Alta (8) | 1.8% | — | Totolink X5000r Firmware | 14/5/2024 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function. |