Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.35% | — | Totolink X5000r Firmware | 24/2/2026 | 5/7/2026 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1) without sufficient bounds checking. When lighttpd s request size limit is not enforced, a crafted… | |
| Analizada | Crítica (9.8) | 0.72% | — | Totolink X5000r Firmware | 23/2/2026 | 17/6/2026 | TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through CsteSystem without validating if the input starts with a hyphen (-). This allows… | |
| Analizada | Alta (8) | 3.3% | — | Totolink X5000r Firmware | 23/2/2026 | 17/6/2026 | TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without adequate validation or filtering. This… | |
| Analizada | Baja (2.1) | 2.8% | — | Totolink X5000r Firmware | 13/12/2025 | 30/9/2026 | A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulation of the argument User causes os command injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Crítica (9.8) | 11% | — | Totolink X5000r Firmware | 10/12/2025 | 25/9/2026 | Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the same implementation, may also be affected. | |
| Analizada | Baja (2.1) | 3.7% | — | Totolink X5000r Firmware | 4/9/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Analizada | Media (6.5) | 0.79% | — | Totolink X5000r Firmware | 21/2/2025 | 17/6/2026 | Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua. | |
| Analizada | Media (6.5) | 0.79% | — | Totolink X5000r Firmware | 21/2/2025 | 17/6/2026 | Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua. | |
| Analizada | Media (6.8) | 1.4% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiScheduleCfg. | |
| Analizada | Media (6.8) | 1.5% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in setWiFiScheduleCfg. | |
| Analizada | Media (6.8) | 1.4% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in setWiFiScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAccountCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg. | |
| Modificada | Alta (8.8) | 1.2% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg. | |
| Modificada | Alta (8.8) | 1.7% | — | Totolink X5000r Firmware | 15/1/2025 | 17/6/2026 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg. | |
| Analizada | Media (6.8) | 2.7% | — | Totolink X5000r Firmware | 13/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.6% | — | Totolink X5000r Firmware | 13/8/2024 | 17/6/2026 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. |