Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2552▼ 400 respecto a la semana anterior
Críticas / altas1318▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.9) | 7.3% | — | Totolink N300rhAI | 31/5/2026 | 22/7/2026 | A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is possible to be carried… | |
| Aplazada | Alta (8.9) | 3.3% | — | Totolink N300rhAI | 26/5/2026 | 23/7/2026 | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument mac_address results in buffer overflow. The attack may be launched remotely. The exploit is… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink N300RH 3.2.4-B20220812. This affects the function setWanConfig of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument priDns leads to buffer overflow. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 0.79% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executing a manipulation of the argument FileName can lead to buffer overflow. The attack can be launched remotely. The exploit… | |
| Aplazada | Alta (8.9) | 1.0% | — | Totolink N300rhAI | 4/5/2026 | 17/6/2026 | A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument Password results in buffer overflow. The attack can be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.53% | — | Totolink N300rhAI | 2/5/2026 | 17/6/2026 | A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 2.1% | — | Totolink N300rhAI | 13/4/2026 | 17/6/2026 | A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgrade.so. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 2.9% | — | Totolink N300rh Firmware | 8/3/2026 | 17/6/2026 | A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation results in os command injection. The attack can be initiated remotely. The exploit has been made public and… | |
| Analizada | Alta (8.9) | 4.5% | — | Totolink N300rh Firmware | 27/2/2026 | 17/6/2026 | A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be… | |
| Analizada | Baja (2) | 0.55% | — | Totolink N300rh Firmware | 21/6/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message Handler. The manipulation of the argument url leads to denial of service. The exploit has been disclosed to the public… | |
| Analizada | Alta (7.4) | 0.96% | — | Totolink N300rh Firmware | 21/6/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formPortFw of the component HTTP POST Message Handler. The manipulation of the argument service_type leads to buffer overflow. The attack may be launched… | |
| Analizada | Media (5.3) | 1.5% | — | Totolink N300rh Firmware | 18/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in TOTOLINK N300RH 6.1c.1390_B20191101. This vulnerability affects the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 1.2% | — | Totolink N300rh Firmware | 18/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in TOTOLINK N300RH 6.1c.1390_B20191101. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name leads to command injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 1.5% | — | Totolink N300rh Firmware | 18/5/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been rated as critical. Affected by this issue is the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument url leads to command injection. The attack may be launched remotely. The exploit has… | |
| Modificada | Alta (8.8) | 4.2% | — | Totolink A3002r FirmwareTotolink A3002ru-v1 FirmwareTotolink A3002ru-v2 FirmwareTotolink A702r-v2 Firmware+9 | 9/12/2020 | 17/6/2026 | TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router. | |
| Modificada | Crítica (9.8) | 4.4% | — | Totolink A850r-v1 FirmwareTotolink F1-v2 FirmwareTotolink F2-v1 FirmwareTotolink N150rt-v2 Firmware+4 | 24/11/2020 | 17/6/2026 | An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd sysCmd parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Totolink A850r-v1 FirmwareTotolink F1-v2 FirmwareTotolink F2-v1 FirmwareTotolink N150rt-v2 Firmware+4 | 24/11/2020 | 17/6/2026 | An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet to the WAN interface, it is possible to open the web management interface on the WAN interface. |