Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.33% | — | Totolink T6AI | 28/8/2026 | 1/9/2026 | Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Media (5.5) | 2.1% | — | Totolink N600rAI | 25/8/2026 | 26/8/2026 | A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Aplazada | Crítica (9.3) | 1.1% | — | Totolink N600rAI | 25/8/2026 | 27/8/2026 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack… | |
| Aplazada | Media (5.7) | 0.66% | — | Totolink Ex1200lAI | 17/8/2026 | 20/8/2026 | A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null pointer dereference. The attack can be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.7) | 0.66% | — | Totolink Ex1200lAI | 17/8/2026 | 20/8/2026 | A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Password Configuration Handler. The manipulation leads to null pointer dereference. The attack can be initiated remotely. The… | |
| Aplazada | Alta (7.4) | 0.85% | — | Totolink A800rAI | 14/8/2026 | 18/8/2026 | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.85% | — | Totolink A800rAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly… | |
| Aplazada | Alta (7.4) | 0.85% | — | Totolink A800rAI | 14/8/2026 | 14/8/2026 | A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The… | |
| Aplazada | Alta (7.4) | 0.85% | — | Totolink A800rAI | 14/8/2026 | 18/8/2026 | A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It is possible to initiate the attack… | |
| Aplazada | Alta (7.4) | 0.85% | — | Totolink A800rAI | 14/8/2026 | 14/8/2026 | A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack… | |
| Aplazada | Alta (7.4) | 0.85% | — | Totolink A800rAI | 14/8/2026 | 14/8/2026 | A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to initiate the attack remotely. The… | |
| Aplazada | Alta (7.4) | 0.85% | — | Totolink A800rAI | 14/8/2026 | 18/8/2026 | A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The… | |
| Aplazada | Alta (7.4) | 0.85% | — | Totolink A800rAI | 14/8/2026 | 14/8/2026 | A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Aplazada | Alta (7.4) | 0.85% | — | Totolink A800rAI | 14/8/2026 | 18/8/2026 | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The… | |
| Aplazada | Alta (8.9) | 1.1% | — | Totolink Nr1800xAILighttpdAI | 14/7/2026 | 15/7/2026 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Aplazada | Alta (7.7) | 0.71% | — | Totolink A3000ruAITotolink A3100rAITotolink A950rgAITotolink Ac1200t10AI+3 | 9/7/2026 | 3/9/2026 | A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. The manipulation leads to least privilege violation. The attack may… | |
| Aplazada | Media (5.5) | 0.67% | — | Totolink X5000rAI | 9/7/2026 | 14/7/2026 | A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely. | |
| Aplazada | Crítica (9.4) | 0.31% | — | Totolink Ex1200lAI | 23/6/2026 | 23/6/2026 | Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as… | |
| Aplazada | Media (5.5) | 0.29% | — | Totolink Ex200AIVsftpdAI | 9/6/2026 | 23/7/2026 | A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results in least privilege violation. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Baja (2.1) | 0.21% | — | Totolink Cp450AIVsftpdAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2.1) | 0.21% | — | Totolink Ac1200 T8AIVsftpdAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Alta (8.9) | 7.3% | 💥 PoC | Totolink N300rhAI | 31/5/2026 | 22/7/2026 | A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is possible to be carried… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink N300rhAI | 26/5/2026 | 23/7/2026 | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink Ca750-poeAI | 26/5/2026 | 23/7/2026 | A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published… | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink Ca750-poeAI | 26/5/2026 | 23/7/2026 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate the attack remotely.… |