Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 1/9/2026 | 1/9/2026 | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Media (5.9) | 0.43% | — | Totolink T6AI | 1/9/2026 | 1/9/2026 | Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (5.9) | 0.43% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (5.3) | 0.40% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (5.3) | 0.40% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 31/8/2026 | Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (5.3) | 0.41% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 31/8/2026 | Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a custom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 31/8/2026 | Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.47% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |