Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
1436 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.29% | — | Totolink N150rtAI | 29/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition… | |
| Aplazada | Alta (8.8) | 0.28% | — | Totolink N150rtAI | 29/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field. | |
| Aplazada | Alta (8.8) | 0.33% | — | Totolink N150rtAI | 29/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control / URL filter configuration handler) and is triggered by the url request parameter when the addFilterUrl (or… | |
| Aplazada | Alta (8.6) | 1.9% | — | Totolink N150rtAI | 28/9/2026 | 28/9/2026 | A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Alta (8.6) | 2.3% | — | Totolink A3002muAI | 19/9/2026 | 21/9/2026 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Totolink A3002muAI | 19/9/2026 | 22/9/2026 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the… | |
| Aplazada | Crítica (9.3) | 0.88% | — | Totolink A3002muAI | 18/9/2026 | 21/9/2026 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 18/9/2026 | 23/9/2026 | A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 18/9/2026 | 22/9/2026 | A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink X5000rAI | 15/9/2026 | 16/9/2026 | A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation of the argument filetype leads to os command injection. The attack can be… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Totolink X5000rAI | 15/9/2026 | 22/9/2026 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access. | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 14/9/2026 | 16/9/2026 | A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may… | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 14/9/2026 | 14/9/2026 | A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be… | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 14/9/2026 | 15/9/2026 | A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 14/9/2026 | 15/9/2026 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Baja (2) | 0.35% | — | Totolink A3002muAI | 14/9/2026 | 14/9/2026 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Alta (8.6) | 0.79% | — | Totolink Cp450AI | 3/9/2026 | 3/9/2026 | A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component.. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Alta (7.5) | 0.47% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Alta (7.5) | 0.60% | — | Totolink T6AI | 1/9/2026 | 1/9/2026 | Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component. |