Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)20%—Totolink Ex200 Firmware21/11/202417/6/2026
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.
AnalizadaAlta (8.7)1.3%—Totolink Ex200 Firmware1/8/202417/6/2026
A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed…
AnalizadaAlta (8.7)1.2%—Totolink Ex200 Firmware1/8/202417/6/2026
A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_host leads to buffer overflow. It is possible to launch the attack remotely. The exploit has…
AnalizadaCrítica (9.8)0.61%—Totolink Ex200 Firmware14/5/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
AnalizadaMedia (6.8)0.57%—Totolink Ex200 Firmware18/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.
AnalizadaBaja (2.4)0.49%—Totolink Ex200 Firmware18/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.
AnalizadaAlta (7.5)55%—Totolink Ex200 Firmware8/4/202417/6/2026
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.
AnalizadaAlta (7.5)2.7%—Totolink Ex200 Firmware8/4/202417/6/2026
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.
AnalizadaCrítica (9.1)0.58%—Totolink Ex200 Firmware8/4/202417/6/2026
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh
AnalizadaAlta (8.8)8.3%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.
AnalizadaAlta (8.4)0.20%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.
AnalizadaMedia (6.5)0.34%—Totolink Ex200 Firmware8/4/202417/6/2026
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.
AnalizadaAlta (8)0.97%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.
AnalizadaAlta (8.8)0.98%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.
AnalizadaAlta (8.8)0.93%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.
AnalizadaCrítica (9.8)1.4%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.
AnalizadaMedia (6.5)0.39%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.
AnalizadaMedia (6.5)0.50%—Totolink Ex200 Firmware8/4/202417/6/2026
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.
ModificadaCrítica (9.8)38%—Totolink Ex200 Firmware4/1/202217/6/2026
The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.