Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the interval parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the week parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the recHour parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the mode parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the hour parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the dhcpMtu parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the ttlWay parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Crítica (9.8) | 1.4% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunPort parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Crítica (9.8) | 1.4% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Crítica (9.8) | 1.4% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun_user parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Crítica (9.8) | 1.4% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the url parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeServiceName parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the pppoeMtu parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the provider parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Media (6.5) | 0.67% | — | Totolink A3300r Firmware | 23/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the password parameter to /cgi-bin/cstecgi.cgi. | |
| Analizada | Crítica (9.8) | 1.4% | — | Totolink A3300r Firmware | 9/4/2026 | 17/6/2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parameter to /cgi-bin/cstecgi.cgi. | |
| Aplazada | Baja (2) | 2.5% | — | Totolink A3300rAI | 6/4/2026 | 24/7/2026 | A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command injection. The exploit has been disclosed publicly and may be used. | |
| Analizada | Baja (2.1) | 3.5% | — | Totolink A3300r Firmware | 31/3/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument vlanPriLan3 leads to command injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Baja (2.1) | 3.5% | — | Totolink A3300r Firmware | 31/3/2026 | 17/6/2026 | A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument rxRate can lead to command injection. The attack may be launched remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 3.0% | — | Totolink A3300r Firmware | 31/3/2026 | 17/6/2026 | A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument provided results in command injection. The attack may be initiated remotely. The exploit has been released to the public and… |