Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.47% | — | Dlink Dir-605l Firmware | 4/5/2026 | 17/6/2026 | D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir605l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument mac_address results in buffer overflow. The attack may be launched remotely. The exploit is… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink N300RH 3.2.4-B20220812. This affects the function setWanConfig of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument priDns leads to buffer overflow. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executing a manipulation of the argument FileName can lead to buffer overflow. The attack can be launched remotely. The exploit… | |
| Aplazada | Alta (8.9) | 1.0% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument Password results in buffer overflow. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink WA300 5.2cu.7112_B20190227. This affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument hostTime leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A weakness has been identified in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument langType causes command injection. Remote exploitation of the attack is possible. The… | |
| Aplazada | Alta (8.9) | 1.0% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument http_host results in buffer overflow. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A vulnerability was identified in Totolink WA300 5.2cu.7112_B20190227. Impacted is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument webWlanIdx leads to command injection. The attack may be initiated remotely. The exploit is publicly… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink Wa300AI | 4/5/2026 | 17/6/2026 | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. This issue affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executing a manipulation of the argument File can lead to buffer overflow. The attack can be launched remotely. The exploit… | |
| Analizada | Baja (2.1) | 4.4% | — | Wavlink Wl-wn570ha1 Firmware | 3/5/2026 | 17/6/2026 | A vulnerability was detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. The affected element is the function ping_ddns of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument DDNS results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. Once again… | |
| Analizada | Baja (2.1) | 4.4% | — | Wavlink Wl-wn570ha1 Firmware | 3/5/2026 | 17/6/2026 | A security vulnerability has been detected in Wavlink WL-WN570HA1 R70HA1 V1410_221110. Impacted is the function set_sys_cmd of the file /cgi-bin/adm.cgi. Such manipulation of the argument command leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Baja (2.1) | 6.0% | — | Wavlink Wl-wn570ha1 Firmware | 3/5/2026 | 17/6/2026 | A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation of the argument Username causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Aplazada | Media (5.5) | 0.53% | — | Totolink N300rhAI | 2/5/2026 | 17/6/2026 | A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Aplazada | Media (6.4) | 0.35% | — | Quantumcloud Simple Link DirectoryAI | 2/5/2026 | 17/6/2026 | The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to insufficient input sanitization and output escaping on user supplied attributes such as `title_font_size`. This makes it… | |
| Analizada | Baja (2.9) | 2.6% | — | Dlink M60 Firmware | 1/5/2026 | 17/6/2026 | A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the file /usr/bin/httpd. This manipulation causes weak password recovery. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be… | |
| Aplazada | Alta (7.4) | 2.9% | — | Totolink Nr1800xAI | 1/5/2026 | 17/6/2026 | A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Aplazada | Alta (8.9) | 1.0% | — | Totolink Nr1800xAILighttpdAI | 1/5/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink A8000ruAI | 1/5/2026 | 17/6/2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument proto leads to os command injection. The attack may be initiated remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.44% | — | LinkstackAI | 30/4/2026 | 17/6/2026 | A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Baja (2) | 0.35% | — | LinkstackAI | 30/4/2026 | 17/6/2026 | A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made… | |
| Aplazada | Crítica (9.8) | 1.8% | — | Totolink N200reAI | 29/4/2026 | 17/6/2026 | TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function. | |
| Aplazada | Alta (7.5) | 0.46% | — | Totolink A3002ruAI | 29/4/2026 | 17/6/2026 | TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname parameter in the formMapDelDevice function. | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-825m Firmware | 28/4/2026 | 17/6/2026 | A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-825m Firmware | 28/4/2026 | 17/6/2026 | A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may… |