Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
1429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 2.1% | — | Totolink X6000rAI | 6/10/2026 | 6/10/2026 | A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed… | |
| Aplazada | Baja (2.1) | 0.35% | — | Totolink A3002muAI | 5/10/2026 | 6/10/2026 | A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and… | |
| Aplazada | Crítica (9.3) | 0.64% | — | Totolink A3002muAI | 5/10/2026 | 6/10/2026 | A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is… | |
| Aplazada | Crítica (9.3) | 0.78% | — | Totolink A3002muAI | 5/10/2026 | 6/10/2026 | A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to… | |
| Aplazada | Crítica (9.8) | 0.29% | — | Totolink N150rtAI | 29/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition… | |
| Aplazada | Alta (8.8) | 0.28% | — | Totolink N150rtAI | 29/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field. | |
| Aplazada | Alta (8.8) | 0.33% | — | Totolink N150rtAI | 29/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control / URL filter configuration handler) and is triggered by the url request parameter when the addFilterUrl (or… | |
| Aplazada | Alta (8.6) | 1.9% | — | Totolink N150rtAI | 28/9/2026 | 28/9/2026 | A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Alta (8.6) | 2.3% | — | Totolink A3002muAI | 19/9/2026 | 21/9/2026 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Totolink A3002muAI | 19/9/2026 | 22/9/2026 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the… | |
| Aplazada | Crítica (9.3) | 0.88% | — | Totolink A3002muAI | 18/9/2026 | 21/9/2026 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 18/9/2026 | 23/9/2026 | A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 18/9/2026 | 22/9/2026 | A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink X5000rAI | 15/9/2026 | 16/9/2026 | A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation of the argument filetype leads to os command injection. The attack can be… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Totolink X5000rAI | 15/9/2026 | 22/9/2026 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access. | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 14/9/2026 | 16/9/2026 | A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may… | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 14/9/2026 | 14/9/2026 | A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be… | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 14/9/2026 | 15/9/2026 | A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 14/9/2026 | 15/9/2026 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Baja (2) | 0.35% | — | Totolink A3002muAI | 14/9/2026 | 14/9/2026 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Alta (8.6) | 0.79% | — | Totolink Cp450AI | 3/9/2026 | 3/9/2026 | A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component.. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Alta (7.5) | 0.47% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component. |