Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 1/12/2023 | 17/6/2026 | An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 30/11/2023 | 17/6/2026 | In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Totolink X6000r Firmware | 31/10/2023 | 17/6/2026 | An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component. | |
| Modificada | Crítica (9.8) | 1.2% | — | Totolink X6000r Firmware | 31/10/2023 | 17/6/2026 | An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function. | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink X6000r Firmware | 31/10/2023 | 17/6/2026 | TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function. | |
| Modificada | Alta (7.5) | 0.54% | — | Totolink X6000r Firmware | 31/10/2023 | 17/6/2026 | TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authentication. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink X6000r Firmware | 25/10/2023 | 17/6/2026 | TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function. |