Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.31% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh configurations via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (5.4) | 0.31% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter when Wi-Fi is available via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firewall policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wireless behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose an internal host via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose internal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.47% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter dynamic DNS state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.47% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.62% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.60% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 3/9/2026 | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |