Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)1.0%—Totolink T10 Firmware19/12/202517/6/2026
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument loginAuthUrl leads to stack-based buffer overflow. The attack may be performed from remote.
AnalizadaBaja (2.3)0.14%—Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+95/9/202517/6/2026
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.
AnalizadaAlta (7.5)0.29%—Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+95/9/202517/6/2026
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
AnalizadaBaja (2.3)0.22%—Ecovacs Deebot X1S PRO FirmwareEcovacs Deebot X1 PRO Omni FirmwareEcovacs Deebot X1 Omni FirmwareEcovacs Deebot X1 Turbo Firmware+95/9/202517/6/2026
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
AnalizadaMedia (5.5)11%—Totolink T10 Firmware27/8/202517/6/2026
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
ModificadaCrítica (9.8)0.34%—Totolink A7100ru FirmwareTotolink A950rg FirmwareTotolink T10 Firmware21/7/20255/7/2026
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.
AnalizadaAlta (7.4)0.96%—Totolink T10 Firmware16/6/202517/6/2026
A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ssid5g leads to buffer overflow. The attack can be launched remotely.…
AnalizadaAlta (7.4)0.96%—Totolink T10 Firmware16/6/202517/6/2026
A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The…
AnalizadaBaja (1.1)0.40%—Totolink T10 Firmware16/6/202525/9/2026
A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can only be initiated within the local network. The complexity of an…
AnalizadaAlta (7.4)11%—Totolink T10 Firmware10/6/202517/6/2026
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument Password leads to buffer overflow. The attack may be launched…
AnalizadaAlta (7.4)11%—Totolink T10 Firmware10/6/202517/6/2026
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument device_name leads to buffer overflow. The attack can be…
AnalizadaAlta (7.4)11%—Totolink T10 Firmware10/6/202517/6/2026
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The…
AnalizadaAlta (7.4)5.9%—Totolink T10 Firmware9/6/202517/6/2026
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument slaveIpList leads to buffer overflow. The attack may be initiated remotely. The…
AnalizadaAlta (7.4)6.2%—Totolink T10 Firmware9/6/202517/6/2026
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument File leads to buffer overflow. The attack can be initiated…
AnalizadaAlta (8.7)1.2%—Totolink A3000ru FirmwareTotolink A810r FirmwareTotolink T10 FirmwareTotolink A3100r Firmware+310/5/202517/6/2026
A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffer overflow. The…
ModificadaAlta (7.7)0.22%—Ecovacs Deebot 900 FirmwareEcovacs Deebot N8 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+1023/1/202517/6/2026
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
AnalizadaCrítica (9.5)0.35%—Ecovacs Deebot X2 Omni FirmwareEcovacs Deebot X2 Combo FirmwareEcovacs Deebot X2S FirmwareEcovacs Deebot X5 PRO Firmware+1623/1/202517/6/2026
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
AnalizadaBaja (1.8)0.21%—Ecovacs Deebot N8 FirmwareEcovacs Deebot 900 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+1023/1/202517/6/2026
ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.
AnalizadaMedia (4.8)0.15%—Ecovacs Deebot 900 FirmwareEcovacs Deebot N8 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+1023/1/202517/6/2026
ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism.
AnalizadaMedia (5.3)0.33%—Ecovacs Deebot N10 FirmwareEcovacs Deebot T10 FirmwareEcovacs Deebot X1 FirmwareEcovacs Deebot T20 Firmware+1023/1/202517/6/2026
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
AnalizadaAlta (7)0.40%—Ecovacs Deebot 900 FirmwareEcovacs Deebot N8 FirmwareEcovacs Deebot T8 FirmwareEcovacs Deebot N9 Firmware+1023/1/202517/6/2026
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.
AnalizadaMedia (5.3)3.3%—Totolink T10 Firmware19/9/202417/6/2026
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be initiated remotely. The exploit has been…
AnalizadaAlta (8.7)1.1%—Totolink T8 FirmwareTotolink T10 Firmware8/9/202417/6/2026
A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setStaticDhcpRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc leads to buffer overflow. The attack can be…
AnalizadaAlta (8.7)1.1%—Totolink T8 FirmwareTotolink T10 Firmware8/9/202417/6/2026
A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been classified as critical. Affected is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack…
ModificadaAlta (8.7)1.4%—Totolink T8 FirmwareTotolink T10 Firmware8/9/202417/6/2026
A vulnerability, which was classified as critical, was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. This affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc/week/sTime/eTime leads to buffer overflow. It is possible to initiate…