Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1440 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Totolink X5000r Firmware | 31/5/2023 | 17/6/2026 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function. | |
| Modificada | Media (5.5) | 0.28% | — | Totolink N200re Firmware | 18/5/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is possible to launch the attack on the local… | |
| Modificada | Crítica (9.8) | 1.3% | — | Totolink A3300r Firmware | 18/5/2023 | 9/7/2026 | TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi. | |
| Modificada | Crítica (9.8) | 2.9% | — | Totolink Cp300+ Firmware | 16/5/2023 | 17/6/2026 | A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet. | |
| Modificada | Media (5.5) | 0.24% | — | In-toto Project In-toto | 10/5/2023 | 17/6/2026 | in-toto is a framework to protect supply chain integrity. The in-toto configuration is read from various directories and allows users to configure the behavior of the framework. The files are from directories following the XDG base directory specification. In versions 1.4.0 and prior, among the files read is… | |
| Modificada | Crítica (9.8) | 2.1% | — | Totolink A7100ru Firmware | 5/5/2023 | 17/6/2026 | TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload. | |
| Modificada | Crítica (9.8) | 2.1% | — | Totolink A7100ru Firmware | 5/5/2023 | 17/6/2026 | TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection. | |
| Modificada | Crítica (9.8) | 26% | 💥 Exploit | Totolink X5000r Firmware | 5/5/2023 | 17/6/2026 | TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter. | |
| Modificada | Crítica (9.8) | 2.1% | — | Totolink X18 Firmware | 14/4/2023 | 17/6/2026 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink X18 Firmware | 14/4/2023 | 17/6/2026 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink X18 Firmware | 14/4/2023 | 17/6/2026 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink X18 Firmware | 14/4/2023 | 17/6/2026 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink X18 Firmware | 14/4/2023 | 17/6/2026 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink X18 Firmware | 14/4/2023 | 17/6/2026 | TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink A7100ru Firmware | 7/4/2023 | 17/6/2026 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink A7100ru Firmware | 7/4/2023 | 17/6/2026 | TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules. | |
| Modificada | Crítica (9.8) | 1.9% | — | Totolink A7100ru Firmware | 28/3/2023 | 17/6/2026 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink A7100ru Firmware | 28/3/2023 | 17/6/2026 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at /setting/setWanIeCfg. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink A7100ru Firmware | 28/3/2023 | 17/6/2026 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg. | |
| Modificada | Crítica (9.8) | 2.4% | — | Totolink Cp900 Firmware | 24/3/2023 | 17/6/2026 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Modificada | Crítica (9.8) | 1.4% | — | Totolink Cp900 Firmware | 23/3/2023 | 17/6/2026 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Modificada | Crítica (9.8) | 1.4% | — | Totolink Cp900 Firmware | 23/3/2023 | 17/6/2026 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Modificada | Crítica (9.8) | 2.0% | — | Totolink A7100ru Firmware | 23/3/2023 | 17/6/2026 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg. | |
| Modificada | Crítica (9.8) | 0.68% | — | Totolink Cp900 Firmware | 23/3/2023 | 17/6/2026 | A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service, | |
| Modificada | Crítica (9.8) | 4.7% | — | Totolink Cp900 Firmware | 23/3/2023 | 17/6/2026 | TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. |