Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2767▼ 5 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 207 respecto a la semana anterior
6793 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.23% | — | Linksys Re7000 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012). The arplookup function parses lines from /proc/net/arp using sscanf("%16s ... %18s ..."), storing results into buffers v6 (12 bytes) and v7 (20 bytes). Since the format… | |
| Modificada | Media (5.9) | 0.21% | — | Linksys E7350 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032). The function sub_4045A8 reads up to 256 bytes from /sys/class/net/%s/address into a local buffer and then copies it into caller-provided buffer a1 using strcpy without boundary checks. Since a1 is… | |
| Modificada | Alta (7.5) | 1.1% | — | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function improperly concatenates user-supplied CGI parameters (route_ipaddr_0~3, route_netmask_0~3, route_gateway_0~3) into fixed-size buffers (v6, v10,… | |
| Modificada | Alta (8.4) | 0.23% | — | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_mac use sscanf with overly permissive "%100s" format specifiers to parse entries from /proc/net/arp into fixed-size… | |
| Modificada | Alta (8.8) | 0.71% | — | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functions copy user-supplied input from the "url" CGI parameter into stack buffers (v36, v29) using sprintf without bounds checking. Because these buffers are… | |
| Modificada | Alta (8.8) | 3.9% | 💥 Exploit | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to four user-supplied CGI parameters matching <parameter>_0~3 into a fixed-size buffer (a2) without bounds checking. Remote… | |
| Modificada | Media (5.4) | 18% | 💥 Exploit | Linksys E1200 Firmware | 13/11/2025 | 22/7/2026 | An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, ttcp_size) are concatenated into system… | |
| Modificada | Media (6.5) | 0.52% | — | Totolink Lr1200gb FirmwareTotolink Nr1800x Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads the "IpAddress" parameter from a web request and copies it into a fixed-size stack buffer using… | |
| Modificada | Media (6.5) | 6.6% | — | Totolink Lr1200gb Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi binary (sub_41EC68 function). The binary reads the "imei" parameter from a web request and verifies only that it is 15 characters long. The parameter is then directly… | |
| Modificada | Media (5.1) | 0.22% | — | Totolink A720r FirmwareTotolink Lr1200gb FirmwareTotolink Nr1800x Firmware | 13/11/2025 | 5/7/2026 | A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using sscanf() with "%s" format specifiers… | |
| Modificada | Media (5.1) | 0.22% | — | Totolink A720r Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file using fgets() into a local buffer and subsequently parses the line using sscanf() into a single-byte variable with the %s format specifier.… | |
| Modificada | Media (6.5) | 0.52% | — | Totolink Lr1200gb FirmwareTotolink Nr1800x Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings using sprintf() into fixed-size stack… | |
| Modificada | Media (6.5) | 1.0% | — | Totolink A720r Firmware | 13/11/2025 | 5/7/2026 | A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handles network interface reinitialization from '/var/system/linux_vlan_reinit'. Input is only partially validated by checking the prefix of… | |
| Modificada | Media (6.5) | 1.5% | — | Totolink A720r Firmware | 13/11/2025 | 5/7/2026 | A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell commands and executed… | |
| Aplazada | Alta (7.5) | 0.46% | — | Michaeluno Auto Amazon LinksAI | 11/11/2025 | 17/6/2026 | The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the contents of arbitrary… | |
| Analizada | Alta (7.5) | 0.37% | — | Totolink A7000r Firmware | 10/11/2025 | 17/6/2026 | Se descubrió que TOTOLink A7000R V9.1.0u.6115_B20201022 contenía un desbordamiento de pila en el parámetro addEffect de la función urldecode. Esta vulnerabilidad permite a los atacantes causar una Denegación de Servicio (DoS) mediante una solicitud POST manipulada. | |
| Analizada | Alta (7.5) | 0.37% | — | Totolink A7000r Firmware | 10/11/2025 | 17/6/2026 | TOTOLink A7000R V9.1.0u.6115_B20201022 se descubrió que contenía un desbordamiento de pila en el parámetro ssid de la función urldecode. Esta vulnerabilidad permite a los atacantes causar una Denegación de Servicio (DoS) mediante una solicitud manipulada. | |
| Analizada | Crítica (9.3) | 4.0% | — | Dlink Dir-1260 Firmware | 6/11/2025 | 17/6/2026 | El firmware del router Wi-Fi D-Link DIR-1260, versiones hasta e incluyendo v1.20B05, contiene una vulnerabilidad de inyección de comandos dentro de la interfaz de gestión web que permite a atacantes no autenticados ejecutar comandos arbitrarios en el dispositivo con privilegios de root. La falla específicamente existe… | |
| Analizada | Media (4.4) | 0.10% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this vulnerability leading to Denial of service. | |
| Analizada | Media (6.7) | 0.14% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database to obtain confidential information. | |
| Analizada | Media (6.7) | 0.37% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell CloudLink. | |
| Analizada | Alta (7.2) | 0.33% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of system. | |
| Analizada | Alta (8.4) | 0.65% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell access of system. | |
| Analizada | Crítica (9.1) | 0.38% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server and gain access of shell and escalate privilege, gain unauthorized access of system. If ssh is enabled with web credentials of server, attack is… | |
| Analizada | Alta (7.2) | 1.0% | — | Dell Cloudlink | 5/11/2025 | 17/6/2026 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system. |