Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.6) | 0.47% | — | Netgear Lbr1020 FirmwareNetgear Lbr20 FirmwareNetgear R6700ax FirmwareNetgear R7800 Firmware+18 | 9/6/2026 | 23/7/2026 | Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations. | |
| Analizada | Media (4.2) | 0.28% | — | Netgear Rbe970 FirmwareNetgear Rbr350 FirmwareNetgear Rbr760 FirmwareNetgear Rbs350 Firmware+1 | 9/6/2026 | 23/7/2026 | An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this… | |
| Analizada | Alta (7.4) | 1.0% | — | Totolink Lr350 Firmware | 27/3/2026 | 17/6/2026 | A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (7.4) | 0.72% | — | Totolink Lr350 Firmware | 19/1/2026 | 17/6/2026 | A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack can be initiated remotely. The… | |
| Analizada | Alta (7.4) | 1.0% | — | Totolink Lr350 Firmware | 19/1/2026 | 17/6/2026 | A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (7.4) | 0.72% | — | Totolink Lr350 Firmware | 19/1/2026 | 17/6/2026 | A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may… | |
| Analizada | Alta (7.4) | 0.92% | — | Totolink Lr350 Firmware | 19/1/2026 | 17/6/2026 | A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could… | |
| Analizada | Baja (2.1) | 2.7% | — | Totolink Lr350 Firmware | 19/1/2026 | 17/6/2026 | A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 3.1% | — | Totolink Lr350 Firmware | 19/1/2026 | 17/6/2026 | A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument ip leads to command injection. The attack can be initiated remotely. The exploit is publicly… | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Alta (7.5) | 0.41% | — | Totolink Lr350 Firmware | 31/10/2025 | 17/6/2026 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Analizada | Media (4.9) | 0.31% | — | Dell Poweredge R770 FirmwareDell Poweredge R670 FirmwareDell Poweredge R570 FirmwareDell Poweredge R470 Firmware+108 | 25/9/2025 | 17/6/2026 | Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Modificada | Crítica (10) | 13% | — | Engeniustech Esr300 FirmwareEngeniustech Esr350 FirmwareEngeniustech Esr600 FirmwareEngeniustech Esr900 Firmware+3 | 24/6/2025 | 17/6/2026 | An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with… | |
| Analizada | Media (6.9) | 1.6% | — | Totolink Lr350 Firmware | 1/11/2024 | 17/6/2026 | A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 0.60% | — | Totolink Lr350 Firmware | 15/8/2024 | 17/6/2026 | Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh. | |
| Modificada | Media (5.3) | 3.2% | — | Totolink Lr350 Firmware | 30/7/2024 | 17/6/2026 | A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Affected by this vulnerability is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to command injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 1.4% | — | Totolink Lr350 Firmware | 3/6/2024 | 17/6/2026 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function. | |
| Analizada | Crítica (9.8) | 6.1% | — | Totolink Lr350 Firmware | 24/5/2024 | 17/6/2026 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth. | |
| Analizada | Crítica (9.8) | 0.84% | — | Totolink Lr350 Firmware | 14/5/2024 | 17/6/2026 | TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth. | |
| Analizada | Alta (8.8) | 0.56% | — | Totolink Lr350 Firmware | 14/5/2024 | 17/6/2026 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode. |