Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 1.1% | — | Totolink Ex1800t Firmware | 17/3/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316. It has been declared as critical. Affected by this vulnerability is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliSsid leads to stack-based buffer overflow. The attack can be… | |
| Analizada | Alta (8.7) | 1.1% | — | Totolink Ex1800t Firmware | 17/3/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316. It has been classified as critical. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument admpass leads to stack-based buffer overflow. It is possible to launch the attack remotely. The… | |
| Analizada | Alta (8.7) | 7.2% | — | Totolink Ex1800t Firmware | 7/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue affects the function setRptWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument loginpass leads to stack-based buffer overflow. The attack may be initiated remotely. The… | |
| Analizada | Media (5.3) | 2.8% | — | Totolink Ex1800t Firmware | 7/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mode/week/minute/recHour leads to os command injection. The attack can be initiated remotely. The… | |
| Analizada | Media (5.3) | 2.8% | — | Totolink Ex1800t Firmware | 7/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 13% | — | Totolink Ex1800t Firmware | 7/3/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliKey/key leads to os command injection. The attack may be launched remotely. The… | |
| Analizada | Alta (8.7) | 0.87% | — | Totolink Ex1800t Firmware | 3/3/2025 | 17/6/2026 | A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.75% | — | Totolink Ex1800t Firmware | 9/12/2024 | 17/6/2026 | A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 3.8% | — | Totolink Ex1800t Firmware | 8/5/2024 | 17/6/2026 | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges. | |
| Modificada | Crítica (9.8) | 1.6% | — | Totolink Ex1800t Firmware | 12/1/2024 | 17/6/2026 | TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface | |
| Modificada | Crítica (9.8) | 0.97% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 0.97% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 0.97% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langType’ parameter of the setLanguageCfg interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 0.97% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘key5g’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 1.0% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 0.97% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 1.0% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 1.0% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi | |
| Modificada | Crítica (9.8) | 1.0% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi | |
| Modificada | Crítica (9.8) | 0.97% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanNetmask parameter’ of the setLanConfig interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 0.97% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanGateway parameter’ of the setLanConfig interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 0.97% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanPriDns parameter’ of the setLanConfig interface of the cstecgi .cgi | |
| Modificada | Crítica (9.8) | 1.0% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtenderConfig interface of the cstecgi.cgi. | |
| Modificada | Crítica (9.8) | 0.97% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘apcliAuthMode’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi. | |
| Modificada | Crítica (9.8) | 1.0% | — | Totolink Ex1800t Firmware | 22/12/2023 | 17/6/2026 | TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi. |