Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.85%—Totolink A800rAI14/8/202618/8/2026
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been…
AplazadaAlta (7.4)0.85%—Totolink A800rAI14/8/202614/8/2026
A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly…
AplazadaAlta (7.4)0.85%—Totolink A800rAI14/8/202614/8/2026
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The…
AplazadaAlta (7.4)0.85%—Totolink A800rAI14/8/202618/8/2026
A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It is possible to initiate the attack…
AplazadaAlta (7.4)0.85%—Totolink A800rAI14/8/202614/8/2026
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack…
AplazadaAlta (7.4)0.85%—Totolink A800rAI14/8/202614/8/2026
A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Performing a manipulation of the argument macAddress results in stack-based buffer overflow. It is possible to initiate the attack remotely. The…
AplazadaAlta (7.4)0.85%—Totolink A800rAI14/8/202618/8/2026
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The…
AplazadaAlta (7.4)0.85%—Totolink A800rAI14/8/202614/8/2026
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component product.so. This manipulation of the argument File causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit…
AplazadaAlta (7.4)0.85%—Totolink A800rAI14/8/202618/8/2026
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The…
AplazadaAlta (7.4)0.79%—Totolink A800rAI13/4/202617/6/2026
A vulnerability was detected in Totolink A800R 4.1.2cu.5137_B20200730. This impacts the function setAppEasyWizardConfig in the library /lib/cste_modules/app.so. The manipulation of the argument apcliSsid results in buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
AnalizadaAlta (8.7)1.2%—Totolink A3000ru FirmwareTotolink A810r FirmwareTotolink T10 FirmwareTotolink A3100r Firmware+310/5/202517/6/2026
A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffer overflow. The…
AnalizadaAlta (7.3)0.39%—Totolink A800r Firmware23/4/202517/6/2026
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.
AnalizadaAlta (7.3)0.48%—Totolink A800r Firmware23/4/202517/6/2026
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component
AnalizadaAlta (7.3)0.42%—Totolink A800r Firmware23/4/202517/6/2026
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.
AnalizadaMedia (6.5)1.2%—Totolink A800r Firmware23/4/202517/6/2026
TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.
AnalizadaCrítica (9.8)1.3%—Totolink A950rg FirmwareTotolink A810r FirmwareTotolink A800r FirmwareTotolink A830r Firmware+222/4/202517/6/2026
TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
AnalizadaCrítica (9.8)1.3%—Totolink A830r FirmwareTotolink A3100r FirmwareTotolink A810r FirmwareTotolink A800r Firmware+222/4/202517/6/2026
TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
AnalizadaCrítica (9.8)1.3%—Totolink A800r FirmwareTotolink A810r FirmwareTotolink A830r FirmwareTotolink A950rg Firmware+222/4/202517/6/2026
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the…
AnalizadaAlta (7.3)0.39%—Totolink A800r FirmwareTotolink A810r FirmwareTotolink A830r FirmwareTotolink A950rg Firmware+222/4/202517/6/2026
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpTo parameter.
AnalizadaAlta (7.3)0.34%—Totolink A800r FirmwareTotolink A810r FirmwareTotolink A830r FirmwareTotolink A950rg Firmware+222/4/202517/6/2026
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm parameter.
AnalizadaMedia (6.5)0.30%—Totolink A800r Firmware15/4/202517/6/2026
TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.
ModificadaCrítica (9.8)1.1%—Totolink A800r Firmware27/3/202517/6/2026
The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
ModificadaAlta (7.8)0.30%—Totolink A800r Firmware29/8/202217/6/2026
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
ModificadaAlta (7.2)3.3%—Totolink A830r FirmwareTotolink A3100r FirmwareTotolink A950rg FirmwareTotolink A800r Firmware+26/7/202217/6/2026
Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B20200730, Totolink A3000RU V5.9c.5185_B20201128, Totolink A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability.
ModificadaCrítica (9.8)2.8%—Totolink A830r FirmwareTotolink A3100r FirmwareTotolink A950rg FirmwareTotolink A800r Firmware+215/3/202217/6/2026
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows…