Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.52% | — | Totolink Lr1200gb FirmwareTotolink Nr1800x Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads the "IpAddress" parameter from a web request and copies it into a fixed-size stack buffer using… | |
| Modificada | Media (6.5) | 6.6% | — | Totolink Lr1200gb Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi binary (sub_41EC68 function). The binary reads the "imei" parameter from a web request and verifies only that it is 15 characters long. The parameter is then directly… | |
| Modificada | Media (5.1) | 0.22% | — | Totolink A720r FirmwareTotolink Lr1200gb FirmwareTotolink Nr1800x Firmware | 13/11/2025 | 5/7/2026 | A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using sscanf() with "%s" format specifiers… | |
| Modificada | Media (6.5) | 0.52% | — | Totolink Lr1200gb FirmwareTotolink Nr1800x Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings using sprintf() into fixed-size stack… | |
| Analizada | Crítica (9.8) | 2.0% | — | Totolink Lr1200gb Firmware | 23/2/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi of the component Web Interface. The manipulation of the argument http_host leads to stack-based buffer overflow. It is possible to… | |
| Modificada | Crítica (9.8) | 1.1% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.99% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument lang leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.99% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been declared as critical. This vulnerability affects the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument sPort leads to stack-based buffer overflow. The attack can be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 1.1% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been classified as critical. This affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The… | |
| Modificada | Crítica (9.8) | 1.1% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument sTime leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 1.1% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability has been found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 1.3% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument pppoeUser leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 1.3% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. This issue affects the function setSmsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument text leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. This affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to os command injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to os command injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 4.8% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this vulnerability is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 4.9% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Alta (8.8) | 4.4% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 8.7% | — | Totolink Lr1200gb Firmware | 31/10/2023 | 17/6/2026 | TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth. |