Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
1429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.79% | — | Totolink A3700r FirmwareTotolink N600r Firmware | 25/9/2023 | 9/7/2026 | TOTOLINK A3700R V9.1.2u.6134_B20201202 y N600R V5.3c.5137 son vulnerables a un control de acceso incorrecto. | |
| Modificada | Alta (8.8) | 3.7% | — | Totolink N200re-v5 Firmware | 4/9/2023 | 17/6/2026 | Una vulnerabilidad clasificada como crítica se ha encontrado en TOTOLINK N200RE V5 9.3.5u.6437_B20230519. Esto afecta a la comprobación de validez. La manipulación conduce a formatear la cadena. Es posible iniciar el ataque de forma remota. La causa principal de la vulnerabilidad es un problema de cadena de formato.… | |
| Modificada | Crítica (9.8) | 1.7% | — | Totolink X5000r Firmware | 21/8/2023 | 17/6/2026 | TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface. | |
| Modificada | Crítica (9.8) | 1.7% | — | Totolink X5000r Firmware | 21/8/2023 | 17/6/2026 | TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function. | |
| Modificada | Crítica (9.8) | 3.7% | — | Totolink Ex1200l Firmware | 18/8/2023 | 17/6/2026 | A vulnerability was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This issue affects the function setWanCfg. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of… | |
| Modificada | Crítica (9.8) | 5.2% | — | Totolink Ex1200l Firmware | 18/8/2023 | 17/6/2026 | A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 3.7% | — | Totolink Ex1200l Firmware | 18/8/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 1.5% | — | Totolink T10 V2 Firmware | 8/8/2023 | 17/6/2026 | TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code. | |
| Modificada | Crítica (9.8) | 1.0% | — | Totolink T10 V2 Firmware | 8/8/2023 | 17/6/2026 | TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code. | |
| Modificada | Alta (7.5) | 0.83% | — | Totolink Cp300+ Firmware | 17/7/2023 | 17/6/2026 | TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink A3300r Firmware | 7/7/2023 | 17/6/2026 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink A3300r Firmware | 7/7/2023 | 17/6/2026 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink A3300r Firmware | 7/7/2023 | 17/6/2026 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function. | |
| Modificada | Crítica (9.8) | 1.7% | — | Totolink A3300r Firmware | 7/7/2023 | 17/6/2026 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink Lr350 Firmware | 7/7/2023 | 17/6/2026 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink Lr350 Firmware | 7/7/2023 | 17/6/2026 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink Lr350 Firmware | 7/7/2023 | 17/6/2026 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink Lr350 Firmware | 7/7/2023 | 17/6/2026 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink A7100ru Firmware | 7/6/2023 | 17/6/2026 | Se descubrió que TOTOLink A7100RU V7.4cu.2313_B20191024 contenía una vulnerabilidad de inyección de comandos a través del parámetro staticGw en /setting/setWanIeCfg. | |
| Modificada | Crítica (9.8) | 3.1% | — | Totolink X5000r Firmware | 6/6/2023 | 9/7/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function. | |
| Modificada | Crítica (9.8) | 1.4% | — | Totolink X5000r Firmware | 31/5/2023 | 17/6/2026 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter. | |
| Modificada | Crítica (9.8) | 1.4% | — | Totolink X5000r Firmware | 31/5/2023 | 17/6/2026 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter. | |
| Modificada | Alta (8.8) | 1.1% | — | Totolink X5000r Firmware | 31/5/2023 | 17/6/2026 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function. | |
| Modificada | Media (5.5) | 0.28% | — | Totolink N200re Firmware | 18/5/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is possible to launch the attack on the local… | |
| Modificada | Crítica (9.8) | 1.3% | — | Totolink A3300r Firmware | 18/5/2023 | 9/7/2026 | TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi. |