Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.83% | — | Totolink A3002r Firmware | 6/9/2022 | 17/6/2026 | TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in binary /bin/boa. | |
| Modificada | Crítica (9.8) | 0.88% | — | Totolink A3002r Firmware | 6/9/2022 | 17/6/2026 | In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware. | |
| Modificada | Alta (7.5) | 0.83% | — | Totolink A3002r Firmware | 6/9/2022 | 17/6/2026 | TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa. | |
| Modificada | Crítica (9.8) | 0.86% | — | Totolink A3002r Firmware | 6/9/2022 | 17/6/2026 | TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa. | |
| Modificada | Media (6.1) | 29% | — | Totolink A3002r Firmware | 20/8/2021 | 17/6/2026 | Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Description" field and "Service Name" field. | |
| Modificada | Media (6.1) | 0.66% | — | Totolink A3002r Firmware | 20/8/2021 | 17/6/2026 | Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "URL Address" field. | |
| Modificada | Media (6.1) | 0.66% | — | Totolink A3002r Firmware | 20/8/2021 | 17/6/2026 | Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "User Name" field or "Password" field. | |
| Modificada | Media (5.3) | 0.81% | — | Totolink A3002r Firmware | 20/8/2021 | 17/6/2026 | Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /add/ , /img/, /js/, and /mobile directories via GET Parameter. | |
| Modificada | Media (6.1) | 0.66% | — | Totolink A3002r Firmware | 20/8/2021 | 17/6/2026 | Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Service Name" field. | |
| Modificada | Media (6.1) | 0.66% | — | Totolink A3002r Firmware | 20/8/2021 | 17/6/2026 | Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers to execute arbitrary JavaScript by modifying the "Domain Name" field, "Server Address" field, "User Name/Email", or "Password/Key" field. | |
| Modificada | Alta (8.8) | 4.2% | — | Totolink A3002r FirmwareTotolink A3002ru-v1 FirmwareTotolink A3002ru-v2 FirmwareTotolink A702r-v2 Firmware+9 | 9/12/2020 | 17/6/2026 | TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router. |