Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the upload or flash workflow via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.62% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.60% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or weaken guest wireless access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 3/9/2026 | Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or disable wireless networks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 2/9/2026 | Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 31/8/2026 | Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 31/8/2026 | Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.62% | — | Totolink T6AI | 31/8/2026 | 31/8/2026 | Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.47% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.50% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgrade status and affect upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (7.5) | 0.47% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Alta (8.6) | 3.3% | — | Dlink Dns-340lAIDlink Dns-345AI | 31/8/2026 | 31/8/2026 | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Media (4.3) | 0.29% | — | Totolink T6AI | 31/8/2026 | 1/9/2026 | Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |