Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.85%—Totolink Nr1800xAI31/8/20261/9/2026
A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
AplazadaBaja (2.1)1.8%—Totolink Nr1800xAI31/8/202631/8/2026
A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
AplazadaAlta (8.9)1.1%—Totolink Nr1800xAILighttpdAI14/7/202615/7/2026
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit…
AplazadaAlta (7.4)2.9%—Totolink Nr1800xAI1/5/202617/6/2026
A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
AplazadaAlta (8.9)1.0%—Totolink Nr1800xAILighttpdAI1/5/202617/6/2026
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly…
AnalizadaBaja (2.1)3.7%—Totolink Nr1800x Firmware29/3/202617/6/2026
A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation of the argument host_time leads to command injection. The attack can be initiated remotely. The exploit has been…
AnalizadaAlta (7.4)0.85%—Totolink Nr1800x Firmware22/1/202617/6/2026
A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. Impacted is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack may be initiated remotely. The exploit is now…
AnalizadaBaja (2.1)2.9%—Totolink Nr1800x Firmware22/1/202617/6/2026
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Such manipulation of the argument command leads to command injection. The attack can be launched remotely. The…
AnalizadaBaja (2.1)3.5%—Totolink Nr1800x Firmware22/1/202617/6/2026
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has…
ModificadaMedia (6.5)0.52%—Totolink Lr1200gb FirmwareTotolink Nr1800x Firmware13/11/20255/7/2026
A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads the "IpAddress" parameter from a web request and copies it into a fixed-size stack buffer using…
ModificadaMedia (5.1)0.22%—Totolink A720r FirmwareTotolink Lr1200gb FirmwareTotolink Nr1800x Firmware13/11/20255/7/2026
A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using sscanf() with "%s" format specifiers…
ModificadaMedia (6.5)0.52%—Totolink Lr1200gb FirmwareTotolink Nr1800x Firmware13/11/20255/7/2026
A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings using sprintf() into fixed-size stack…
AnalizadaAlta (8.8)0.71%—Totolink Nr1800x Firmware8/5/202517/6/2026
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function.
AnalizadaAlta (8.8)0.71%—Totolink Nr1800x Firmware8/5/202517/6/2026
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.
AnalizadaAlta (8.8)0.71%—Totolink Nr1800x Firmware8/5/202517/6/2026
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.
AnalizadaAlta (8.8)0.91%—Totolink Nr1800x Firmware8/5/202517/6/2026
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.
AnalizadaCrítica (9.8)0.53%—Totolink Nr1800x Firmware8/5/202517/6/2026
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
AnalizadaAlta (8.8)2.5%—Totolink Nr1800x Firmware24/5/202417/6/2026
TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode
ModificadaCrítica (9.8)1.5%—Totolink Nr1800x Firmware9/1/202417/6/2026
A vulnerability was found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. Affected by this issue is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been…
ModificadaCrítica (9.8)0.70%—Totolink Nr1800x Firmware16/10/202317/6/2026
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
ModificadaAlta (8.8)2.2%—Totolink Nr1800x Firmware23/11/202217/6/2026
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.
ModificadaAlta (8.8)1.0%—Totolink Nr1800x Firmware6/10/202217/6/2026
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
ModificadaAlta (8.8)1.0%—Totolink Nr1800x Firmware6/10/202217/6/2026
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.
ModificadaAlta (8.8)1.0%—Totolink Nr1800x Firmware6/10/202217/6/2026
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg function.
ModificadaCrítica (9.8)1.9%—Totolink Nr1800x Firmware6/10/202217/6/2026
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.
Orbitaley — Vulnerabilidades