Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 20% | — | Totolink Ex200 Firmware | 21/11/2024 | 17/6/2026 | TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter. | |
| Analizada | Alta (8.7) | 1.3% | — | Totolink Ex200 Firmware | 1/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed… | |
| Analizada | Alta (8.7) | 1.2% | — | Totolink Ex200 Firmware | 1/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_host leads to buffer overflow. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.61% | — | Totolink Ex200 Firmware | 14/5/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | |
| Analizada | Media (6.8) | 0.57% | — | Totolink Ex200 Firmware | 18/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function. | |
| Analizada | Baja (2.4) | 0.49% | — | Totolink Ex200 Firmware | 18/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function. | |
| Analizada | Alta (7.5) | 55% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg. | |
| Analizada | Alta (7.5) | 2.7% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg. | |
| Analizada | Crítica (9.1) | 0.58% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh | |
| Analizada | Alta (8.8) | 8.3% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function. | |
| Analizada | Alta (8.4) | 0.20% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default. | |
| Analizada | Media (6.5) | 0.34% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig. | |
| Analizada | Alta (8) | 0.97% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function. | |
| Analizada | Alta (8.8) | 0.98% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function. | |
| Analizada | Alta (8.8) | 0.93% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function. | |
| Analizada | Crítica (9.8) | 1.4% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function. | |
| Analizada | Media (6.5) | 0.39% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization. | |
| Analizada | Media (6.5) | 0.50% | — | Totolink Ex200 Firmware | 8/4/2024 | 17/6/2026 | TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function. | |
| Modificada | Crítica (9.8) | 38% | — | Totolink Ex200 Firmware | 4/1/2022 | 17/6/2026 | The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution. |