Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware1/12/202317/6/2026
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware30/11/202317/6/2026
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
ModificadaCrítica (9.8)1.2%—Totolink X6000r Firmware31/10/202317/6/2026
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.
ModificadaCrítica (9.8)1.2%—Totolink X6000r Firmware31/10/202317/6/2026
An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.
ModificadaCrítica (9.8)1.5%—Totolink X6000r Firmware31/10/202317/6/2026
TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.
ModificadaAlta (7.5)0.54%—Totolink X6000r Firmware31/10/202317/6/2026
TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.
ModificadaCrítica (9.8)1.9%—Totolink X6000r Firmware25/10/202317/6/2026
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.
Orbitaley — Vulnerabilidades