Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.34% | — | Totolink A3300r FirmwareTotolink N200re Firmware | 15/12/2025 | 17/6/2026 | TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Attackers can send payloads to the interface without logging in (remote). | |
| Analizada | Media (6.5) | 1.1% | — | Totolink N200re Firmware | 15/12/2025 | 17/6/2026 | TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName. | |
| Analizada | Baja (2.1) | 2.4% | — | Totolink N200re Firmware | 8/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Hostname leads to os command injection. The attack may be launched… | |
| Modificada | Alta (7.2) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Totolink N200RE 9.3.5u.6139_B20201216. This affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument lang leads to stack-based buffer overflow. The attack may be launched remotely. The… | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this vulnerability is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ePort leads to stack-based buffer overflow. The attack can be launched remotely. The exploit… | |
| Modificada | Crítica (9.8) | 1.4% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 1.5% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument eTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit… | |
| Modificada | Alta (8.8) | 1.4% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Alta (8.8) | 1.3% | — | Totolink N200re Firmware | 29/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. Affected by this issue is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument pppoeUser leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink N200re Firmware | 8/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink N200re Firmware | 8/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. Affected is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink N200re Firmware | 8/1/2024 | 17/6/2026 | A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink N200re Firmware | 8/1/2024 | 17/6/2026 | A vulnerability has been found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This vulnerability affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument host_time leads to os command injection. The attack can be initiated remotely. The exploit has… | |
| Modificada | Media (5.5) | 0.28% | — | Totolink N200re Firmware | 18/5/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in TOTOLINK N200RE 9.3.5u.6255_B20211224. Affected is an unknown function of the file /squashfs-root/etc_ro/custom.conf of the component Telnet Service. The manipulation leads to password in configuration file. It is possible to launch the attack on the local… | |
| Modificada | Media (6.1) | 0.57% | — | Totolink N200re FirmwareTotolink N100re Firmware | 2/5/2022 | 17/6/2026 | A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element. | |
| Modificada | Alta (8.8) | 25% | — | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N301rt FirmwareTotolink N302r Firmware+4 | 27/1/2020 | 17/6/2026 | On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through… | |
| Modificada | Alta (7.5) | 6.4% | — | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+14 | 27/1/2020 | 17/6/2026 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through… | |
| Modificada | Alta (7.5) | 8.7% | — | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+14 | 27/1/2020 | 17/6/2026 | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0,… | |
| Modificada | Crítica (9.8) | 30% | — | Totolink A3002ru FirmwareTotolink A702r FirmwareTotolink N301rt FirmwareTotolink N302r Firmware+4 | 27/1/2020 | 17/6/2026 | On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The attacker can perform router actions via… |